Translate this website:
Search this website:


BC/DRCloud StorageComplianceData CentresDeduplicationDisk/RAID/Tape/SSDsEthernet StorageSAN/NASTiered StorageVirtualization

New EU Data Directive will drive turning point for security

By Shaul Efraim Vice President of products, marketing and business development at Tufin Technologies.

 

Date: 4 Jun 2012

The European Commission is planning a raft of new directives on data security that commentators say will come to be seen as an important turning point. The New 24-hour data breach disclosure rules are a golden opportunity for organizations willing to embrace automation.

 

The Directive includes a number of tough new provisions on data handling, but the element that will give security professionals the most immediate anxiety is the insistence that organizations doing business in the 27-nation EU zone inform national information commissioners of data breaches affecting consumers or citizens within 24 hours, or risk heavy fines for not doing so.

 

This is a radical jump. Having been under little or no obligation to formally disclose a data breach in most EU countries, companies will suddenly be required not only to inform the authorities but do so in some detail on an accelerated timescale.  Moreover, the change will affect not only companies in the EU but those doing business in it, making the Directive the first de facto global data breach law.

 

Informing the authorities that a breach has been discovered sounds straightforward but is anything but.  Assuming administrators have evidence that something has gone awry do they have the tools to say precisely what without delay?  What sort of reporting systems do they have to explain the extent of a breach?  Do possible security failures have any regulatory and legal consequences and if so, what?

 

A major consequence of this development is that old-fashioned periodic, manual security audits and the manual configuration processes that underlie them should be viewed heading for obsolescence.

 

Currently, security is often measured for regulatory and compliance purposes through an external audit that takes place quarterly or annually, depending on the business sector. Some organizations also perform more regular internal checks, but the design of these is open to interpretation and their frequency varies from organization to organization.

The reality of the data breach Directive is that administrators could be asked to audit their security stance at any moment in time as a breach is uncovered, with only a few hours notice. Referring back to an audit possibly months or weeks in the past will be useless; CISOs will require an overview of security policies, compliance and data protection that reflects what is happening at the moment the request is made.

 

This makes complete sense - can any company possibility understand its security state using an audit that is possibly months out of date? Here the Directive imposes an important level of discipline organizations should welcome.

 

What such continuous auditing does do is render manual assessment impractical. The solution - automated auditing in real time – goes from being a useful convenience to an essential component of any security infrastructure.

 

Today, realtime security and auditing requires that organizations integrate information from multiple types of hardware system, and across a range of vendors that generate reports through proprietary management consoles. On top of this any reporting infrastructure must also make sense of the flow of security data from different elements of the system, comparing this to a set of security policies. At any moment, security managers must be able to react quickly when a particular setting infringes the policy and have the means to describe what action was taken and why.

 

Although new reporting systems will be needed to build such an infrastructure, a key issue is whether this change from causal to mandatory and continuous auditing will be viewed positively by the people tasked with putting it into practice, the security professionals themselves. This is the biggest unknown of the data breach Directive – how will professionals interpret and react to it?

 

A recent survey of 100 network managers by Tufin Technologies sheds some light, finding 42 percent believing that the Data Breach Directive would lead to an increased risk-awareness within their organization. A third believed that their attitude towards continuous compliance had changed as a result of the new regime, with just over half convinced that automated audits would make it easier to comply with the Directive.

Close up, attitudes probably vary from individual to individual, organization to organization, some seeing the Directive as more of an aspiration, others as the medicine needed by an industry that even after a swathe of data breaches remains complacent. 

According Jericho Forum board member, Andrew Yeomans, the Directive serves to focus security professionals on data security over systems.

 

“From a Jericho Forum viewpoint, any strengthening of regulations is an incentive to implement pervasive data-centric security, so the data is protected wherever it is,” says Yeomans.

 

“The Jericho Forum has highlighted that the ‘perimeterized’ [that is, traditional] model misses many possible breaches, especially data that has been intentionally passed to other organisations, which subsequently suffer a breach.”

 

His worry remains ‘false positives’ which underlines the need for accurate realtime auditing and monitoring. “The regulators may also get overloaded with potential data breach reports that turn out to be false alarms, if only 24 hours is allowed for any initial investigation,” he warns.

 

Far from being an imposition, the arrival of the EU Data Breach Directive could serve as a huge opportunity to impose a rational design on security that rewards the best practices and the companies willing to bring them into effect.

 

As daunting as it appears, the Directive’s biggest plus is its scope, which imposes the same rules across the 27-nation EU zone and beyond. This creates short-term hurdles but the pay-off is potentially huge. For the first time, multi-national organizations will no longer have to interpret a confusing array of data breach and protection rules in different territories, allowing for the sort of policy centralisation that can enhance security. For the first time everyone will be playing by the same rules based on a swift response. 

The world of manual, ad-hoc auditing was always one based on assumptions about risk that now, suddenly, much less certainty attached to them. In a world of uncertain security there is no longer time to waste.  It is critical that organizations approach the toughness of the directive head on using the right tools and processes, with automated auditing to the fore. 

 

New EU Data Directive will drive turning point for security

By Shaul Efraim Vice President of products, marketing and business development at Tufin Technologies.

The European Commission is planning a raft of new directives on data security that commentators say will come to be seen as an important turning point. The New 24-hour data breach disclosure rules are a golden opportunity for organizations willing to embrace automation.

The Directive includes a number of tough new provisions on data handling, but the element that will give security professionals the most immediate anxiety is the insistence that organizations doing business in the 27-nation EU zone inform national information commissioners of data breaches affecting consumers or citizens within 24 hours, or risk heavy fines for not doing so.

This is a radical jump. Having been under little or no obligation to formally disclose a data breach in most EU countries, companies will suddenly be required not only to inform the authorities but do so in some detail on an accelerated timescale. Moreover, the change will affect not only companies in the EU but those doing business in it, making the Directive the first de facto global data breach law.

Informing the authorities that a breach has been discovered sounds straightforward but is anything but. Assuming administrators have evidence that something has gone awry do they have the tools to say precisely what without delay? What sort of reporting systems do they have to explain the extent of a breach? Do possible security failures have any regulatory and legal consequences and if so, what?

A major consequence of this development is that old-fashioned periodic, manual security audits and the manual configuration processes that underlie them should be viewed heading for obsolescence.

Currently, security is often measured for regulatory and compliance purposes through an external audit that takes place quarterly or annually, depending on the business sector. Some organizations also perform more regular internal checks, but the design of these is open to interpretation and their frequency varies from organization to organization.
The reality of the data breach Directive is that administrators could be asked to audit their security stance at any moment in time as a breach is uncovered, with only a few hours notice. Referring back to an audit possibly months or weeks in the past will be useless; CISOs will require an overview of security policies, compliance and data protection that reflects what is happening at the moment the request is made.

This makes complete sense - can any company possibility understand its security state using an audit that is possibly months out of date? Here the Directive imposes an important level of discipline organizations should welcome.

What such continuous auditing does do is render manual assessment impractical. The solution - automated auditing in real time – goes from being a useful convenience to an essential component of any security infrastructure.

Today, realtime security and auditing requires that organizations integrate information from multiple types of hardware system, and across a range of vendors that generate reports through proprietary management consoles. On top of this any reporting infrastructure must also make sense of the flow of security data from different elements of the system, comparing this to a set of security policies. At any moment, security managers must be able to react quickly when a particular setting infringes the policy and have the means to describe what action was taken and why.

Although new reporting systems will be needed to build such an infrastructure, a key issue is whether this change from causal to mandatory and continuous auditing will be viewed positively by the people tasked with putting it into practice, the security professionals themselves. This is the biggest unknown of the data breach Directive – how will professionals interpret and react to it?

A recent survey of 100 network managers by Tufin Technologies sheds some light, finding 42 percent believing that the Data Breach Directive would lead to an increased risk-awareness within their organization. A third believed that their attitude towards continuous compliance had changed as a result of the new regime, with just over half convinced that automated audits would make it easier to comply with the Directive.
Close up, attitudes probably vary from individual to individual, organization to organization, some seeing the Directive as more of an aspiration, others as the medicine needed by an industry that even after a swathe of data breaches remains complacent.
According Jericho Forum board member, Andrew Yeomans, the Directive serves to focus security professionals on data security over systems.

“From a Jericho Forum viewpoint, any strengthening of regulations is an incentive to implement pervasive data-centric security, so the data is protected wherever it is,” says Yeomans.

“The Jericho Forum has highlighted that the ‘perimeterized’ [that is, traditional] model misses many possible breaches, especially data that has been intentionally passed to other organisations, which subsequently suffer a breach.”

His worry remains ‘false positives’ which underlines the need for accurate realtime auditing and monitoring. “The regulators may also get overloaded with potential data breach reports that turn out to be false alarms, if only 24 hours is allowed for any initial investigation,” he warns.

Far from being an imposition, the arrival of the EU Data Breach Directive could serve as a huge opportunity to impose a rational design on security that rewards the best practices and the companies willing to bring them into effect.

As daunting as it appears, the Directive’s biggest plus is its scope, which imposes the same rules across the 27-nation EU zone and beyond. This creates short-term hurdles but the pay-off is potentially huge. For the first time, multi-national organizations will no longer have to interpret a confusing array of data breach and protection rules in different territories, allowing for the sort of policy centralisation that can enhance security. For the first time everyone will be playing by the same rules based on a swift response.
The world of manual, ad-hoc auditing was always one based on assumptions about risk that now, suddenly, much less certainty attached to them. In a world of uncertain security there is no longer time to waste. It is critical that organizations approach the toughness of the directive head on using the right tools and processes, with automated auditing to the fore.


 

ShareThis

« Previous article

Next article »

Tags: BC/DR, Compliance

Related White Papers

23 Nov 2011 | White Papers

Automated Storage Tiering on Infortrend’s ESVA Solution by Infortrend

This white paper introduces automated storage tiering on Infortrend’s ESVA storage solutions. Automated storage tiering can generate significant advant... Download white paper

15 Jul 2010 | White Papers

Is Your Data Safe & Sound? by SecurStore

Ease of recoverability, secure protection and strict compliance policies are all key aspects when backing up data online. Download white paper

Read more White Papers»

Related News

23 May 2013 | BC/DR

23 May 2013 | BC/DR

22 May 2013 | BC/DR

21 May 2013 | BC/DR

Read more News »
Related SNS UK TV & Audio

24 Nov 2011 | BC/DR

IBM Centennial Film: 100 X 100 - A century of achievements that have changed the world

The film features one hundred people, who each present the IBM achievement recorded in the year they were born. The film chronology flows from the oldest person to the youngest, offering a whirlwind history of the company and culminating wi...

14 Oct 2011 | Deduplication

Introducing Quantum's DXi Accent: Maximizing Deduplication Efficiency [Part 2]

Get to know Quantum's DXi Accent software in Part 2 of our video blog introduction by Dan Duperron.

3 Oct 2011 | BC/DR

StoreOnce Backup Systems whiteboard overview

HP StoreOnce Backup systems make it much easier for administrators to deal with the exploding amount of data that they have to manage.

More SNS UK TV»

More Audio»

Related Web Exclusives

6 May 2013 | BC/DR

22 Apr 2013 | BC/DR

15 Apr 2013 | BC/DR

8 Apr 2013 | BC/DR

Read more Web Exclusives»

Related Magazine Articles

| BC/DR

May/June 2010 | Deduplication

March 2010 | Tiered Storage

October 2009 | BC/DR

  • Banking on business continuity

    Premier Asset Management needed to implement a complete business continuity strategy that would meet the company's recovery objectives around its critical busin... Read more

Read more Magazine Articles»

Related Supplements

1 Jun 2009 | Data Centres

Sharpen Your Business

It might be stretching the point to compare the present state of the IT industry with either Charles Dickens? revolutionary-era France, or the Renaissance, but there?s no doubting that the current global economic turmoil is a great opportunity for UK businesses to innovate. For far too long now, many have been content to simply throw more disks at their storage problem; continued to invest in expensive solutions, with after-sales contracts to match, because ?they always have?; and employed muddled thinking when it comes to CAPEX- and OPEX-related decisions.

Click here to learn more »

1 Oct 2008 | Virtualization

Discovering Business Continuity in a Virtualized Environment

At first, organisations saw VMware server virtualization mainly as a way to save money on their hardware and power budgets. Now though, innovative users have realised that virtualization can make vital contributions in many other ways as well - in particular, they are using it to improve application availability and enhance their disaster recovery capabilities.

Click here to learn more »

Read more Supplements »

Recruitment

Latest IT jobs from leading companies.

 

Click here for full listings»