Thursday, August 10, 2017

Demonstrate Data Compliance !


Enterprise data are subject to various regulations depending on their geographical location and type of business. An increased effort is expected and mandated to respect those rules, typically meant to better secure and protect the accuracy and privacy of enterprise data. In various regulations, it is also expected to actually demonstrate Compliance, which is not a piece of cake.
In addition, most people think that external threats (such as an external hacker trying to access corporate data) are the most common data security issues. In reality, various studies have shown that internal threats comprise 80% of all security threats. In other words, companies should make sure to protect their corporate data against their own employees.

Examples of regulations


Sarbanes-Oxley Act (SOX) : The goal of SOX is to regulate corporations in order to reduce fraud and conflicts of interest, to improve disclosure and financial reporting, and to strengthen confidence in public accounting. Specifically, the section 404 of this act, the one giving IT shops fits, specifies that the CFO must do more than simply vow that the company’s finances are accurate; he or she must guarantee the processes used to add up the numbers. Those processes are typically computer programs that access data in a database, and DBAs create and manage that data as well as many of those processes.

Health Insurance Portability and Accountability Act (HIPAA) : This legislation contains language specifying that health care providers must protect individual’s health care information even going so far as to state that the provider must be able to document everyone who even so much as looked at their information. Aka. can a DBA produce a list of everyone who looked at a specific row or set of rows in any database ?

Payment Card Industry & Data Security Standard (PCI DSS) : This well-known standard was developed by the major credit card companies to help prevent credit card fraud, hacking and other security issues. A company processing, storing, or transmitting credit card numbers must be PCI DSS compliant or they risk losing the ability to process credit card payments. Given the availability and volume concerns of payment card transactions this information is typically stored in an enterprise database.

General Data Protection Regulation (GDPR) : This new regulation applies to organizations that do business in the European Union, and will be effective in May 2018. It is meant to strengthen and unify data protection for individuals within the European Union, but it also focuses on the export of data (or even accessing the data) outside the EU. The stated objective of GDPR is to return control of personal data back to the individual. This includes data retention requirements, data privacy rules and huge penalties for being out of compliance.

Personal Information Protection and Electronic Documents Act (PIPEDA) : This Canadian regulation specifies the rules to govern collection, use, or disclosure of the personal information in the course of recognizing the right of privacy of individuals with respect to their personal information. It also specifies the rules for the organizations to collect, use, and disclose personal information.

Demonstrate Compliance!


It’s (almost) as simple as a 1-2-3 process!

Step 1 to Data Compliance : Define Data Compliance for your business

Depending on the type of corporate data you own, the type of business you are in, and the geography you do business with, the regulations you want to comply with will be different. And the definition of Personal Information to protect will be different!
As a typical example, the format of social security numbers is different from one country to another. If you do business in Czech Republic (for example), the social security numbers (Rodné číslo) have a specific format
  [0-9]{2}[0,1,5][0-9][0-9]{2}/?[0-9]{4}
 



Step 2 to Data Compliance : Locate the sensitive personal data

While most companies understand the need to comply to regulation(s), a typical challenge is to determine where all the sensible personal data are actually located within the corporate data.
When you have defined what kind of data you are going after (Step 1), the challenge is to make sure you know where those are stored : where are those “Rodné číslo” in the corporate data ?
You may think you know where all these are stored, but … are you sure? Remember: the goal is to demonstrate compliance, so you better be sure you know exactly where all those “Rodné číslo” are stored.



Step 3 to Data Compliance : Secure, protect, and demonstrate compliance

When you know what personal data you are going after, and you know where they are located, the game is to make sure the authorizations and security settings are defined properly, so that only the individuals that must have access to it… have access to it.
In other words, you need to produce a report that clearly states what personal data are where, and who has access to it.

Find and control regulated mainframe data and classify for compliance with CA Data Content Discovery (DCD) 

Compliance and adherence to regulations is critical to help prevent data breaches.

CA Data Content Discovery helps you identify data exposure risks on z Systems™ by scanning through the mainframe data infrastructure.
By discovering where the data is located, classifying the data to determine sensitivity level and providing comprehensive reporting on the scan results, mission essential data can be protected and exposure risks can be mitigated.



CA Data Content Discovery (DCD) comes with a number of pre-defined classifiers out-of-the-box, to comply with various well-known regulations.
In addition, CA Data Content Discovery (DCD) can be configured to look for sensible industry-specific or country-specific data in your corporate data, aka. you can create custom classifiers such as a “Rodné číslo” (as discussed above) : 

[0-9]{2}[0,1,5][0-9][0-9]{2}/?[0-9]{4}



65 comments:

  1. good post thanks for explaining in detail about data compliance try to improve it in future blogs
    Cloud Computing Training in Chennai

    ReplyDelete
  2. It is amazing and wonderful to visit your site.Thanks for sharing this information,this is useful to me. oracle training in chennai

    ReplyDelete
  3. wonderful article contains lot of valuable information. Very interesting to read this article.I would like to thank you for the efforts you had made for writing this awesome article.
    This article resolved my all queries.good luck an best wishes to the team members.continue posting.learn digital marketing use these following link
    Digital Marketing Course in Chennai

    ReplyDelete
  4. Worth reading! Our experts also have given detailed inputs about these trainings & courses! Presenting here for your reference. Do checkout
    Aws training in chennai & enjoy learning more about it.

    ReplyDelete
  5. Громаднейший список операций даст шанс любому клиенту http://www.yyy517.com/home.php?mod=space&uid=564221&do=profile получить очередную высоту в области интернет продаж. Основная часть функций портала Liopal доступно абсолютно бесплатно. Ответственный портал по написанию сайтов-визиток и подбору ссылок – это Liopal!

    ReplyDelete
  6. Каждый год у людей которых есть проблемы со зрением, появляется все больше и больше. Очки - наиболее нужный и проверенный способ коррекции зрения - солнцезащитные очки спб. На нашем сайте компании ROCKINGLOOK можно приобрести высококачественные оправы и линзы для очков по доступной цене.

    ReplyDelete
  7. Высококачественный ламинат может быть "под дерево", в виде природного камня или гранитной плитки. Сплошь и рядом наблюдается ламинированная плоскость фанеры характерной, необыкновенной структуры и рисунка. Характерной чертой ламинированной пленки https://fanwood.by/v-shklove/shop/fof-fanera считается не только высокое сопротивление влаге, а также присутствие персональной цветовой гаммы.

    ReplyDelete
  8. Девушки в душе cojo.ru

    ReplyDelete
  9. Обучение детей возрастет в наиболее короткий период. Сложности https://slogy.ru/blog/disgrafiya-i-dizorfografiya в значительной степени проще осилить в игровом режиме на тренажере Slogy. Базовые работы рассчитаны лично для определенного ребенка. На портале компании Слоджи доступно огромное число интересных заданий. Развивать умения чтения ребенка довольно легко – для этих целей разработана продвинутая программа обучения Slogy!

    ReplyDelete
  10. Перегруженные автомобили 43 фото https://cojo.ru/avto/peregruzhennye-avtomobili-43-foto/

    ReplyDelete
  11. Элайза Тейлор (35 фото) HD фото https://cojo.ru/

    ReplyDelete
  12. Кара делевинь короткая стрижка 55 лучших фото https://cojo.ru/pricheski-i-strizhki/kara-delevin-korotkaya-strizhka-55-foto/

    ReplyDelete
  13. Полицейская собака смотреть фото https://cojo.ru/zhivotnye/politseyskaya-sobaka-60-foto/

    ReplyDelete
  14. Прически на средние волосы каре милые картинки https://cojo.ru/pricheski-i-strizhki/pricheski-na-srednie-volosy-kare-44-foto/

    ReplyDelete
  15. Шейлин Вудли в хорошем качестве https://cojo.ru/znamenitosti/sheylin-vudli-42-foto/

    ReplyDelete
  16. Наклейки рыболовные милые картинки https://cojo.ru/grafika/nakleyki-rybolovnye-36-foto/

    ReplyDelete
  17. Картинки успеха фотографии https://cojo.ru/kartinki/kartinki-uspeha-62-foto/

    ReplyDelete
  18. Абиссинская кошка окрасы подборка https://cojo.ru/zhivotnye/abissinskaya-koshka-okrasy-44-foto/

    ReplyDelete
  19. Открытка на день рождения с коньяком милые картинки https://cojo.ru/pozdravleniya/otkrytka-na-den-rozhdeniya-s-konyakom-25-foto/

    ReplyDelete
  20. Aot Scenery Wallpapers WallpapersHigh.com high definition 100% free https://wallpapershigh.com/aot-scenery

    ReplyDelete
  21. Aston Martin Logo Wallpapers WallpapersHigh.com FULL HD absolutely free https://wallpapershigh.com/aston-martin-logo

    ReplyDelete
  22. Bathroom Wall Waterproof Bathroom Wallpapers wallpapershigh.com Fullhd 100% free https://wallpapershigh.com/bathroom-wall-waterproof-bathroom

    ReplyDelete
  23. Bentley Flying Spur Wallpapers wallpapershigh.com High Res absolutely free https://wallpapershigh.com/bentley-flying-spur

    ReplyDelete
  24. Alone Sad Wallpapers wallpapershigh.com UHD 100% free https://wallpapershigh.com/alone-sad

    ReplyDelete
  25. High Resolution Sky Image WallpapersHigh.com HIGH RES for free https://wallpapershigh.com/high-resolution-sky-image

    ReplyDelete
  26. Aspirant Wallpapers wallpapershigh.com High Definition 100% free https://wallpapershigh.com/aspirant

    ReplyDelete
  27. Lockscreen Army BTS Wallpapers https://wallpapershigh.com/ https://wallpapershigh.com/lockscreen-army-bts

    ReplyDelete
  28. Влагостойкая фанера ФСФ - область применения https://fanwood.by/shop/dsp-dvp-i-mdf/

    ReplyDelete
  29. Final Fantasy Xiv Wallpapers wallpapershigh.com https://wallpapershigh.com/final-fantasy-xiv

    ReplyDelete
  30. If you don't remember this, your car may be stolen!

    Imagine that your car was taken! When you visit the police, they inquire about a particular "VIN check"

    A VIN decoder is what?

    Similar to a passport, the "VIN decoder" allows you to find out the date of the car's birth and the identity of its "parent" (manufacturing facility). You can also find out:

    1.Type of engine

    2.Model of a car

    3.The limitations of the DMV

    4.Number of drivers in this vehicle

    The location of the car will be visible to you, and keeping in mind the code ensures your safety. The code can be checked in the database online. The VIN is situated on various parts of the car to make it harder for thieves to steal, such as the first person seated on the floor, the frame (often in trucks and SUVs), the spar, and other areas.

    What if the VIN is intentionally harmed?

    There are numerous circumstances that can result in VIN damage, but failing to have one will have unpleasant repercussions because it is illegal to intentionally harm a VIN in order to avoid going to jail or the police. You could receive a fine of up to 80,000 rubles and spend two years in jail. You might be stopped by an instructor on the road.

    Conclusion.

    The VIN decoder may help to save your car from theft. But where can you check the car reality? This is why we exist– VIN decoders!

    ReplyDelete
  31. Johnny Cage Wallpapers Wallpapershigh.com https://wallpapershigh.com/johnny-cage

    ReplyDelete
  32. ДВП https://fanwood.by/shop/dsp-dvp-i-mdf/ считается довольно общеизвестным отделочным сырьем в строительной сфере. Обклеенная с одной или двух сторон тончайшей пленкой, фанера способна как можно больше противостоять дождю. Присутствует немыслимое число типов водостойкой фанеры, каковой является ламинированная ФОФ.

    ReplyDelete
  33. Влагостойкая фанера ФСФ - среда использования https://fanwood.by/

    ReplyDelete
  34. Покрытая с одной или двух сторон полиэтиленовой пленкой, фанера способна как можно больше сопротивляться дождю. Водится огромное число типов высококачественной фанеры, которой является ламинированная ФОФ. ДВП https://fanwood.by/v-kricheve/shop/fsf-fanera является довольно популярным отделочным материалом в сфере строительства.

    ReplyDelete