Tuesday, February 10, 2009

I should add to my last thought

It is important to know, to identify all of our data. Data loss prevention is a hot topic these days. One of the first steps in DLP is Data Identification. Whether as part of a DLP project or simply as part of a security plan, data identification is always an important step in any security process. If you do not know what you have how can you know how to protect it and what to protect. Simple example, PCI information needs to be protected in specific ways. PII needs to be protected in other specific ways. Do you need to invest the cost and expense needed to protect this information across your entire data center and restrict access to all of your resources? If you know your data and know what is where then you can section off your data and protect the right data to the right level. With that you should also know the regulations and standards that govern your data.

No comments:

Post a Comment