Willie Rushton
Does your company have an issue with data leakage? Is data leakage a concern? The harsh reality is that many companies are unaware of the nature and extent of unauthorized information that is leaving their environment both electronically and physically. However, there are fundamental steps you can take to understand and prevent any potential exposure and risk of leakage of sensitive data.

The first step is to establish a data classification framework for the information within the organization. This is not an IT exercise. This activity must be conducted with the input and participation of the data owners (the staff in finance, marketing, human resources, sales, quality assurance, risk, etc.). I would also suggest keeping those responsible for auditing (internal or external) apprised of all of the classification decisions.

There must be agreement on what level of control should be used for each level of classified information. Conduct a risk assessment based on the output from this exercise and establish a risk acceptance level. Many companies have conducted these steps as part of their regulatory compliance activities.

The next step is to deploy solutions, or configure existing solutions, that will concentrate on logging and tracking the activities focused on your company's information. With many companies tightening belts in the current economic environment, the risk assessment process will help narrow the scope of monitoring to identify exposure. This will potentially provide justification for resource allocation to this more cost-effective solution.

It is also imperative to identify resources to review the outputs of your tools in a proactive mode. Taking this on provides the flexibility needed to review information in a manageable interval. Identifying deficiencies and developing corrective actions is key. It's also vital to perform self-assessments and validate that your processes are working as planned.

And, at least annually, have an independent assessment. This could be done by an internal IT audit team. This will provide you with independent validation. As your process matures and confidence in successful process execution is established, you can reduce the frequency to reduce costs.

This is by no means the complete recipe to solving this issue. The key takeaway is to initiate, or re-initiate, this dialogue within your organization. The days of security by obscurity are behind us. You can't fix what you don't know is broken.


Willie Rushton was formerly director of global information security at Sara Lee.

