How Can Data Protect Itself Beyond the Network?

537 views
•
April 8, 2014
by
RSAC Cybersecurity
YouTube video player
How Can Data Protect Itself Beyond the Network?

TL;DR

Data protection must travel with the data because corporate networks cannot secure files after they move to personal devices, cloud services, or external partners. Effective protection evaluates identity, device condition, connection, location, and data classification, then applies the appropriate access policy, additional verification, or a safer delivery method such as secure application streaming.

Transcript

Well, thanks for being here today. Um, I'm Chad Skipper. This is Elliot Lewis. Um, we're here to tell you that the network, or can we say the corporate network, can no longer protect your data. So with that, we're gonna walk you through, uh, the agenda right quick. I'm gonna walk you through the data journey to get our minds right. Um, and then we'... Read More

Key Insights

  • Corporate network defenses are insufficient once data leaves controlled infrastructure on laptops, personal devices, cloud services, or partner systems. Firewalls, intrusion detection, intrusion prevention, data loss prevention, encryption, and endpoint protections may not observe or govern every movement beyond the network boundary.
  • Data is the primary asset that must remain protected regardless of residence. The military analogy treats the corporate network as headquarters and data as a soldier who needs armor, defensive capabilities, and communication with its owner when operating outside that protected environment.
  • Employee behavior is a major security disruptor because 85 percent of employees use some form of cloud tool. The presentation also describes mobility as growing fivefold and anticipates that employee-owned devices could become the majority of devices used within corporate environments.
  • Destination risk becomes data risk when information moves outside the corporate network. Data transferred to internet storage, personal devices, software-as-a-service infrastructure, or supply-chain partners inherits the security profile of its final location during both use and storage.
  • Identity verification is the first contextual access check. Each protected data object should determine whether the requester is authorized and refuse decryption or visibility immediately when that person has no permission to access the information.
  • Endpoint context determines whether authorized access remains acceptable. Relevant conditions include whether the device is a corporate asset, uses a corporate image, receives corporate monitoring, contains managed controls, operates inside a container, connects through a VPN, or supports application streaming.
  • Data classification determines how much additional protection a situation requires. When sensitive information is accessed outside the corporate network or without a managed device or container, the system can require a second identity factor before allowing the requester to view it.
  • Policy resolution converts multiple applicable rules into one enforcement decision. When one rule permits access and another rejects it, a safer alternative can preserve availability, such as keeping the local file encrypted while streaming a secure copy from the data center.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why can the corporate network no longer protect all data?

The corporate network cannot protect every file because data routinely leaves controlled infrastructure. An employee can download a file to a laptop and carry it outside without the firewall, intrusion detection, intrusion prevention, or data loss prevention systems stopping the movement. The file may then interact with personal devices, cloud services, or external partners whose security posture the organization does not control.

Q: What does it mean for data to protect itself?

Data protecting itself means carrying enough intelligence and enforcement capability to assess access wherever it resides. The data should verify the requester's identity, examine the device and connection, recognize its location and classification, identify applicable policies, and decide whether to decrypt, remain hidden, require additional verification, or provide access through a more secure method.

Q: How does the soldier analogy explain data protection?

The analogy compares a corporate network to military headquarters and data to a soldier. Inside headquarters, perimeter defenses and identity controls provide protection. When the soldier leaves, the soldier needs body armor, weaponry, and communication with headquarters. Similarly, data outside the corporate network needs embedded protections and a way to report its situation so its owner can determine how access should proceed.

Q: What contextual information should protected data evaluate?

Protected data should first determine who is requesting access and whether that person is authorized. It should then evaluate the endpoint, including whether it is managed, monitored, containerized, connected through a VPN, or capable of application streaming. Finally, it should assess where it is and what connections, including Wi-Fi, wired networking, or Bluetooth, are touching the device.

Q: How does data location affect security risk?

Data location affects risk because information inherits the security profile of its destination. Data inside a corporate network probably benefits from more organizational controls. When it moves to internet storage, a personal device, a software-as-a-service environment, or a trusted supply-chain entity, those protections may weaken, and the organization may no longer control the destination's security posture.

Q: When should access require a second authentication factor?

A second authentication factor should be considered when sensitive data is requested under risky conditions. Examples include access outside the corporate network, from an unmanaged device, or without a managed container. Even an authorized requester may be challenged again because a username and password can be lost or compromised, so classification and context together determine whether stronger verification is appropriate.

Q: How should multiple data access policies be resolved?

Multiple policies should be combined into one enforceable decision based on the current requester, device, scenario, location, and data classification. If several policies permit access, the system must determine which result is more restrictive. If one policy permits access and another denies it, conflict-resolution rules should decide whether to reject access or offer a safer authorized method.

Q: How can authorized users access data safely on personal devices?

Authorized users can receive a safer form of access without exposing the local file. If encrypted data sits on a personal device, the system can leave that file encrypted and open an application stream that displays a copy from the data center. This approach avoids a simple denial while keeping the original data protected within the riskier personal-device environment.

Summary & Key Takeaways

  • Corporate network defenses remain useful, but employees routinely move files beyond environments controlled by firewalls, intrusion detection, data loss prevention, and managed endpoints. Once information reaches personal devices, cloud services, or supply-chain partners, it inherits the risks of those destinations and may no longer benefit from corporate security controls.

  • The proposed model gives data a way to assess its own circumstances before allowing access. It first checks whether the requester is authorized, then evaluates the endpoint, corporate controls, containers, VPN use, available application streaming, network connection, physical or logical location, and the sensitivity represented by the data classification.

  • Contextual findings determine which enforcement policies should apply. Sensitive data in a risky environment can trigger another identity check, while overlapping or conflicting policies require resolution. Instead of simply denying authorized users, the system can keep local data encrypted and present a secure copy through application streaming from the data center.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚