Opinion: Current levels of identity theft are inexcusable

  • Email a Friend
  • Print Page
Opinion: Current levels of identity theft are inexcusable
Nov 1, 2008 9:57 AM
Tags: identify | theft | opinion | security

Any IT chief worth their salt knows how to combat data theft, so why is it still so common, asks Ian Schenkel.

With all the noise about the PCI DSS payment card security standard and the importance of protecting data, you might think the situation is under control or at least being addressed seriously.

But potentially hundreds of thousands of records containing personally identifiable information (PII) are still at risk, stored unencrypted and unprotected in databases not subject to PCI DSS compliance. HR databases are a perfect example.

It is ridiculous that PII is being exposed time after time. We know how to solve this problem ­ education combined with good data protection policies and processes.

One of the positive steps a company can take is to institute security awareness training. Ensure that everyone understands how to identify confidential information, the importance of protecting data, how to choose and use passwords, acceptable use of system resources, email, and the firm’s security policies and procedures. Enforce policies with role-based access and auditing.

Security policies should evolve with the times. Consider instituting a weekly meeting with senior managers to talk about data security and regulatory concerns. Look at the data security tools firms use, what threats are out there, and consider what policies the company may need to enact to deal with these issues. Risk analysis should be performed to determine which assets need the most stringent security. And employees’ PII data should be included in security policies.

Data security regulations tend to deal with specific issues rather than addressing the entire network and applications. A system can pass a regulatory audit and still harbour security problems. Work towards comprehensive security rather than simple compliance with regulations.

Data storage guidelines are vague at best and often overlooked or ignored. Data security regulations need to be tightened and strictly enforced if we have any hope of stamping out identity theft.

Ian Schenkel is a BCS contributor, and vice president at Protegrity.

Copyright © 2009 Computing


 
Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
 
Top Stories
TIO website hit by malware
Weekend malware runs one new process per target machine.
 
Microsoft announces Azure launch date
Australia in second wave of country releases.
 
CBA embarks on "database-as-a-service"
Analysis: How the bank intends to save megabucks.
 

Spotlightthe topics we're following

Latest Comments

"Hahahah...What a joke!! "Conroy had said that it was not possible to apply ISP-level filtering ..."
by gerson Feb 9, 2010 10:39 PM
 
"@@Comments, yes, and history keeps repeating itself. Remember the earlier pr-and-media-fuelled ..."
by anonymous Feb 9, 2010 6:40 PM
 
"I would have paid good money to be in court when that clanger dropped. Could you imagine, the ..."
by Private Citizen Feb 9, 2010 6:23 PM
 
"He is not yet listed on NBN Co. website as part of their team of executives (http://www.nbnco.com..."
by Private Citizen Feb 9, 2010 6:07 PM
 
"That would be the list leaked on wikileaks that the minister denied was the ACMA list. The same ..."
by Private Citizen Feb 9, 2010 5:17 PM
1) HTC Magic16 plans 2%
2) Nokia N9743 plans 9%
3) Nokia E7149 plans 1%
4) Apple iPhone 3GS 16GB30 plans 11%
5) Apple iPhone 8GB42 plans 5%
1) iiNet32 plans 5%
2) Netspace36 plans 11%
3) TPG Internet19 plans 14%
4) Optus33 plans 1%
5) Telstra BigPond30 plans 2%

Mobiles | Broadband | Credit Cards

iTnews

Polls

What is the sweet spot for Apple's entry 16GB Wi-Fi iPad?




   |   View results
$549
  78%
 
$579
  10%
 
$619
  4%
 
$649
  3%
 
$699
  5%
TOTAL VOTES: 381

Vote