July 15, 2005

Rethinking the data security box

IBM leaves its (blue)prints all over new data governance council

Computer security can be a difficult problem to get a handle on, so sometimes it takes some creative thinking. I would say it involves "thinking outside the box," but that's a little too trite and overused.

I think of it in a more Zen-like manner -- rethinking the whole box.

I'm sure there's a business book title in that idea somewhere, like Rethinking the Box or Good to Great Boxes. Maybe Who Moved the Box? or Rich Box, Poor Box. Or even Harry Potter and the Magician's Hidden Box.

Something like that.

That kind of rethinking usually comes from smaller, leaner, meaner, and more entrepreneurial companies, such as the once-small Apple Computer or Dell. But it can come from large companies, as well, even from several large companies. This is demonstrated by the creation of the Data Governance Council, a global effort to protect personal and organization data within and between enterprises.

IBM along with a few other IT organizations and several dozen companies, including American Express, Key Bank, Merrill Lynch, TIAA-CREF, and the World Bank, created the council. Their goal? To help technology users find better ways to protect their data against hacker attacks and other security breaches.

The council is working to create a blueprint for the governance and protection of data within companies as the amount of business data continues to grow. According to Gartner, by 2012, companies will need to handle 30 times more business data than they did in 2004.

Data governance looks at how companies permit and govern appropriate access to their critical data by measuring operational risk and mitigating security exposures associated with access to data, said Stuart McIrvine, director of corporate client security strategy at IBM.

Top governance issues that the council will explore include security, privacy, compliance, and risk challenges that need common solutions and standards, as well as misunderstandings regarding organizational and IT roles and behavior, which can potentially cause data exposures, McIrvine added.

"Most companies haven't taken a real data-centric view of their security issues," McIrvine said. "We want to begin building a blueprint where security is thought of from day one, at the beginning of a project."

That doesn't just mean reaching out to software developers, according to McIrvine. "Corporate management needs to be aware that their projects are going to have to take security into account, and that might increase the cost or the time for the project. But the important thing is that they are aware of the need to build that security in."

In other words, this is not one of those projects that just heaps more work on the little guy -- this is going to require work from the big cats, too.

McIrvine said the idea for the council grew out of informal quarterly meetings that IBM has had with customers and business technology partners.

"A lot of us felt like we were dealing with pieces of the [data security] problem, but not really tackling the overall issue," he explained. "That's how this idea came about."

Aside from the blueprint, which will provide a nice tool for planning, several customer members of the council have volunteered to run pilot projects to test new data governance and security technologies in a proof-is-in-the-pudding way.

"That will really show us what works and what doesn't in a real-world environment," McIrvine said.

It's way too early to deem this idea a success, but you can't say these companies didn't think outside the box. Or maybe it's not really thinking outside the box. Maybe it's just thinking -- period.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.