• HOME
  • ABOUT US
    • VISION
    • SOCIAL NETWORK>
      • FACEBOOK SECURITY
      • TWITTER SECURITY
      • SECURITY BLOG
      • SECURITY PRESENTATION
      • JOIN LINKEDIN
      • Ethical Hacking Blog
    • PEOPLE
    • CLIENTS
    • CREDENTIALS
    • MEDIA
  • EGUARD 360
  • SERVICES
    • AUDIT>
      • WEBSITE SECURITY AUDIT
      • APPLICATION SECURITY AUDIT
      • NETWORK SECURITY AUDIT
      • PHYSICAL SECURITY AUDIT
    • COMPLIANCE>
      • ISO 27001 IEC 27002 COMPLIANCE
      • HIPAA COMPLIANCE
      • ISO 20000 COMPLIANCE
      • PCI/DSS
      • TL 9000
    • PENETRATION TESTING
    • MANAGED NETWORK SECURITY
    • MANAGED WEBSITE & APPLICATION SECURITY
    • CONSULTING
    • EMERGENCY RESPONSE & FORENSICS
  • PRODUCTS
    • SECURITY MONITORING
    • GATEWAY SECURITY
    • FORT APPIN ANTI-VIRUS
    • aENCRYPT ENCRYPTION SOFTWARE
  • INDUSTRY FOCUS
    • Aviation & Airlines
    • Telecom & ISP
    • Education Sector
    • BFSI/Banking/Insurance
    • IT / ITES / BPO
    • E-Commerce
    • Government & Defense
    • Health Care & Life Sciences
    • Infrastructure
    • Manufacturing & Engineering
    • Media
    • Retail & FMCG
    • Security Articles>
      • NETWORK SECURITY MANAGEMENT
      • Information security companies
      • WEB APPLICATION SECURITY>
        • Wireless Pen Testing
        • Web Authentication Server
        • Web Application Testing
        • Web App Vulnerability
        • Web Application Monitoring
        • Application Server Monitoring
        • Application Vulnerabilities
        • website security audit
        • Application Security Assessment
        • Application Penetration Testing
        • Juniper firewall india
        • Managed security services
        • Security consultancy service
      • NETWORK SECURITY>
        • TCP IP Stack
        • E-mail Password Encryption
        • Block Port Problem
        • Secured E-mail Server Hosting
        • Infosec Phishing Protection
        • Information Security Policy
        • IT Security Management
        • Intrusion Prevention System
        • Intruder Detection System
        • Internet Security Firewalls
        • Identity Access Management
        • Security Event Log
        • Cyberoam Firewall
        • Network Security Software
        • Antivirus Firewall Software
        • Symantec Antivirus Corporate
        • Sonicwall firewall
        • Online antivirus
        • Best antivirus 2012
        • Hardware Firewall
        • Internet software security suites
      • Industry>
        • Bank Online Application Security
        • Healthcare Hipaa Compliance Security
        • Banking Financial Risk Management
      • CONSULTING AND AUDIT>
        • Security Risk Consultant
        • Enterprise IT Security
        • Corporate Risk Management
        • Audit ISO 9001
        • ISO 27001 Compliance
        • Auditor Wireless Security
        • PCI Compliance Credit Card
        • Network Security Scanner Scan
        • Risk Assesment Management
        • ISO 20000 IT Service
        • ISO 27001
        • TL 9000 telecom
      • Data security>
        • XSS Cross-Site Attack
        • SQL Injection Database
        • Database File Encryption
        • VPN HTTPS System
        • IP Spoofing Data Privacy
        • Man In Middle Attack
        • Data Loss Prevention
        • Data Protection Act
      • Appliance>
        • Voip Voice Encryption
        • IDS IPS UTM Appliance
        • Load Balancer Bandwidth Manager
        • Managed Firewall Services
        • Cisco Mars Pix
        • Firewall Web Server
        • Firewall For Windows Server
  • CONSULTANT
    • BECOME FORT APPIN AUTHORIZED CONSULTANT
    • FORT APPIN AUTHORIZED CONSULTANT LIST>
      • Security-Consulting-Hyderabad-Himayath Nagar
      • Security-Consulting-Hyderabad-Secunderabad
      • Security-Consulting-Hyderabad-Ameerpet
      • Security-Consulting-Rajasthan-Kota
      • Security-Consulting-Bangalore-JP Nagar
      • Security-Consulting-Bangalore-Sahakarnagar
      • Security-Consulting-Mumbai-Thane
      • Security-Consulting-Thiruvananthapuram-Manacuad
  • APPIN GROUP
  • CONTACT US
  • test

_

_ Data Loss Prevention


To best prevent data loss, it is important to first know how data breaches are most likely to occur.

“When it comes to data loss prevention, we often hear about stolen laptop computers and malware downloaded via USB drives, but what we tend not to hear as much about are the instances where organizations overlook the potential of data loss through the use of Web 2.0 tools, such as instant messaging,” “It’s important to keep data security in mind when it comes to instant messaging and other unified communications channels,because IM can act like an open door if left unchecked—it’s imperative that enterprises have tools in place to scan and filter file transfers over IM sessions to protect that data.”

Companies also suffer data loss primarily through ineffective enforcement of company policies. These range from ambiguous rules regarding social networking to the transport of critical data on USB drives to passwords being kept on a computer desktop in a text file.

“While companies often have strict policies regarding the legitimate handling of data, it is often the inadvertent release of sensitive information that can lead to the most serious damage.

Data can flow out of a company through an individual, but more often it flows out through that individual’s computer,“If a company takes each individual computer and implements the same privacy control measures that they would deploy on their personal computers at home, a great deal of unnecessary loss would be prevented. Just as individuals don’t want their Web habits tracked and analyzed by advertising companies, companies should make all efforts to prevent similar behavioral tracking and information exchange from occurring with their employees, especially on company-owned computers.”

As companies become increasingly mobile and users carry company data on portable storage devices (such as USB drives, smartphones and laptops), they increase their risk of data loss.

Data loss can have a minor or major impact on the business. For example, a user might drop a smartphone in a puddle on their way into work. If the phone, which held email correspondence with clients, is rendered useless and the data unrecoverable, then the company suffers a data loss. Luckily that data didn’t get into the wrong hands, and the damage is minimal. But consider a laptop with hundreds of customers’ credit card numbers left on the subway. All those customers are subject to identify theft if the laptop is picked up by an individual with malicious intent and the company is liable.

Data loss isn’t limited to mobile computing devices. Emails containing confidential corporate information can be sent to the wrong recipients. Instant messages can be intercepted by attackers. Weak access controls can allow the wrong users to access sensitive network resources. The methods by which a company can suffer a data loss are numerous and, unfortunately, so are the effects. Data loss can result in negative publicity, damage to the company’s reputation, loss of customers and profits, decreased stock value and even heavy regulatory fines.

In an effort to protect citizens against identity theft, regulatory agencies passed laws requiring companies to protect sensitive information against data loss. These regulations often require the use of encryption, which renders data unreadable and prevents access to it. If a company that is subject to regulatory compliance experiences a data loss without the proper controls, as required by the regulation, the company can be subject to fines and penalties.


Article source: http://www.processor.com/editorial/article.asp?article=articles%2Fp3301%2F36p01x%2F36p01.asp
Article source: http://www.sophos.com/en-us/security-news-trends/security-hubs/data-loss-and-regulations/data-loss-and-regulations-article.aspx