首页> 外文会议>International Conference on Cyber Warfare and Security >How a Nuanced Approach to Organizational Loss may Lead to Improved Policies, Better Applied Technologies, and Greater Outcomes
【24h】

How a Nuanced Approach to Organizational Loss may Lead to Improved Policies, Better Applied Technologies, and Greater Outcomes

机译:组织损失的细微差别方法可能导致改善政策,更好的应用技术和更大的结果

获取原文

摘要

The most common strategic approach to preventing data loss begins with and primarily focuses on three factors: Data In-Use and related integrated endpoint actions and accessibility issues; Data In-Motion, including applied analytics and interwoven network traffic considerations; and Data At-Rest, which incorporates data location, management, storage issues, and post-event analysis. While this common approach provides value, we challenge the assumption that this approach tells the entirety of the data loss story, especially since it is difficult to define true markers of loss. Instead, we assert that data loss prevention strategies deserve a nuanced approach, including a consideration of what data loss truly means to the organization. Our nuanced approach to data loss evaluates what data loss actually means for the organization and factors this into the solution suite an organization employs to prevent the loss. To clearly consider the full data loss story and choose the best individual or combination of solutions, we assert that the organization may need to consider and define data loss according to a number of factors important to the eventual remediation strategy. Headline-making, intentional, and malicious data loss may remain the focus of the traditional approach and the primary consideration for many organizations. But the nuanced approach explored in this paper--which includes unintentional employee data sharing and unintentional data deletion--should also be incorporated into a more encompassing understanding of data loss when determining a strategy and attendant measures. Data loss measurement also requires considerations as to how it is defined by statute and regulation (as disclosure laws differ by region); from whose perspective the loss is evaluated, as various stakeholder perspectives may include business people with a defined interest in the information, information technology professionals who support that work, lawyers (internal and external) to the business, third party contractors, customers, and day-to-day users of the data (especially in those sectors protecting personal data such as health information); and whether the data loss was categorized as confidential or sensitive, thus deserving of protection from unauthorized access or exposure. Based on these additional considerations of risk and stakeholder perspective, we assert that the considerations presented in this paper will provide a better understanding of data loss, and that their utilization will aid organizations when developing more holistic and relevant data loss prevention strategies.
机译:最常见的防止数据损失的战略方法始于并主要关注三个因素:数据使用和相关的集成端点行动和可访问性问题;数据中的数据,包括应用分析和交织网络流量考虑;和休息数据,它包含数据位置,管理,存储问题和事件后分析。虽然这种共同的方法提供了价值,但我们挑战这种方法讲述全部数据丢失故事的假设,特别是因为难以定义真正的损失标记。相反,我们断言数据丢失预防策略值得一种细致的方法,包括考虑数据损失真正意味着组织的方法。我们对数据丢失的细致细节方法评估了组织和因素在解决方案套件中的数据丢失,以防止损失。为了清楚地考虑完整的数据丢失故事并选择最好的个人或解决方案的组合,我们断言,该组织可能需要根据对最终修复策略重要的一些因素来考虑和定义数据丢失。制作,故意和恶意数据丢失可能仍然是传统方法的重点和许多组织的主要考虑因素。但本文探讨的细致细节方法 - 包括无意的员工数据共享和无意的数据删除 - 在确定战略和随访措施时,也应纳入更加涵盖对数据损失的理解。数据丢失测量还需要考虑如何由法规和规定定义(作为区域披露法则);从谁的角度来看,损失被评估,因为各种利益相关者的观点,各种利益相关者的观点可能包括具有界定兴趣的商界人士,支持该工作的信息技术专业人员,律师(内部和外部)到业务,第三方承包商,客户和日 - 日复一日的用户(特别是在保护个人数据等健康信息中的这些部门);以及数据丢失是否分类为机密或敏感,从而应得免受未经授权的访问或曝光。根据这些额外的风险和利益相关者的观点考虑,我们断言本文提出的考虑将更好地了解数据丢失,并且它们的利用将在制定更全面和相关数据丢失预防策略时援助组织。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号