Data-centric security
Data-centric security is an approach to security that emphasizes the security of the data itself rather than the security of networks, servers, or applications. Data-centric security is evolving rapidly as enterprises increasingly rely on digital information to run their business and big data projects become mainstream.[1]
[2]
[3]
Data-centric security also allows organizations to overcome the disconnect between IT security technology and the objectives of business strategy by relating security services directly to the data they implicitly protect; a relationship that is often obscured by the presentation of security as an end in itself.[4]
Key concepts
Common processes in a data-centric security model include:[5]
- Discover: the ability to know what data is stored where including sensitive information.
- Manage: the ability to define access policies that will determine if certain data is accessible, editable, or blocked from specific users, or locations.
- Protect: the ability to defend against data loss or unauthorized use of data and prevent sensitive data from being sent to unauthorized users or locations.
- Monitor: the constant monitoring of data usage to identify meaningful deviations from normal behavior that would point to possible malicious intent.
From a technical point of view, information (data)-centric security relies on the implementation of the following:[6]
- Information (data) that is self-describing and defending.
- Policies and controls that account for business context.
- Information that remains protected as it moves in and out of applications and storage systems, and changing business context.
- Policies that work consistently through the different data management technologies and defensive layers implemented.
Technology
Data access controls and policies
Data access control is the selective restriction of access to data. Accessing may mean viewing, editing, or using. Defining proper access controls requires to map out the information, where it resides, how important it is, who it is important to, how sensitive the data is and then designing appropriate controls.[7]
Encryption
Encryption is a proven data-centric technique to address the risk of data theft in smartphones, laptops, desktops and even servers, including the cloud. One limitation is that encryption is not always effective once a network intrusion has occurred and cybercriminals operate with stolen valid user credentials.[8]
Data masking
Data Masking is the process of hiding specific data within a database table or cell to ensure that data security is maintained and that sensitive information is not exposed to unauthorized personnel. This may include masking the data from users, developers, third-party and outsourcing vendors, etc. Data masking can be achieved multiple ways: by duplicating data to eliminate the subset of the data that needs to be hidden, or by obscuring the data dynamically as users perform requests. [9]
Auditing
Monitoring all activity at the data layer is a key component of a data-centric security strategy. It provides visibility into the types of actions that users and tools have requested and been authorized to on specific data elements. Continuous monitoring at the data layer combined with precise access control can contribute significantly to the real-time detection of data breaches, limits the damages inflicted by a breach and can even stop the intrusion if proper controls are in place. A 2016 survey[10] shows that most organizations still do not assess database activity continuously and lack the capability to identify database breaches in a timely fashion.
Cloud computing
Cloud computing is an evolving paradigm with tremendous momentum, but its unique aspects exacerbate security and privacy challenges. Heterogeneity and diversity of cloud services and environments demand fine-grained access control policies and services that should be flexible enough to capture dynamic, context, or attribute-based access requirements and data protection.[11]
Data-centric security in the public cloud environments
In recent decades many organizations rely on managing database services in public clouds such as Amazon Web Services, Oracle Cloud, Google Cloud Platform or Microsoft Azure to organize their data. Such approaches have their own limitations on what users can do with managing the security of their sensitive data. For instance, hardware security appliances or agents running on the database servers are no longer an option. This requires innovative ways to secure data and databases such as using a reverse proxy sitting in between clients / applications and database servers. The requirements, such as supporting a load balancing, high availability and fail-over in data-centric security bring additional challenges that database security vendors must meet.[12]
See also
- Data masking
- Data security
- Defense in depth (computing)
- Information security
- Information security policies
References
- ^ Gartner Group (2014). "Gartner Says Big Data Needs a Data-Centric Security Focus".
- ^ SANS Institute (2015). "Data-Centric Security Needed to Protect Big Data Implementations".
- ^ IRI (2017). "Masking Big Data in Hadoop and Very Large Databases".
- ^ IEEE (2007). "Elevating the Discussion on Security Management: The Data Centric Paradigm".
- ^ Wired Magazine (2014). "Information-Centric Security: Protect Your Data From the Inside-Out". Archived from the original on 2016-03-27. Retrieved 2015-11-17.
- ^ Mogull, Rich (2014). "The Information-Centric Security Lifecycle" (PDF).
- ^ Federal News Radio (2015). "NASA Glenn becoming more data-centric across many fronts".
- ^ Encryption solutions with multi-factor authentication are much more effective in preventing such access. MIT Technology Review (2015). "Encryption Wouldn't Have Stopped Anthem's Data Breach".
- ^ IRI (2017). "Dynamic Data Masking Software".
- ^ Dark Reading (2016). "Databases Remain Soft Underbelly Of Cybersecurity".
- ^ IEEE (2010). "Security and Privacy Challenges in Cloud Computing Environments" (PDF).
- ^ DataSunrise (2017). "Data-centric database security in the public clouds".