Data Sovereignty



Data Sovereignty: Do you know where your data resides and is it protected?


By Paul Rummery, Securenet Consulting


The continued reports of cloud data breaches and nation states setting out laws for jurisdictional data protection (for example, UK or US based companies having to make sure data does not reside outside of geographical / legal boundaries) have brought the topic of data sovereignty and the questions of 'where is our data actually stored, and is it secure' to the forefront of board tables and senior management discussions.

Data sovereignty should however not be thought of exclusively to data in the cloud (although this is presently the source of concern - the not knowing). 

It is about ensuring your company, corporate valuable / sensitive data / information stays within your defined network perimeter (that includes your primary datacentre / network or private cloud, branch and home offices, mobile devices, public cloud data centres and third party cloud-based app and storage services) or within legal jurisdictional regions - is at the very least, safe from unauthorised access or sharing. 

The problem is, data / files / documents are very easy to copy and replicate at the click of a button or touch of a screen.  
Data sovereignty has just become more of a issue or risk due to the wide spread and rapid adoption of cloud services, either by businesses or the combined issue of employees using unprotected consumer devices to access corporate data sources and then sending or storing data outside the corporate perimeter (most of the big cloud service providers have data centres that store or replicate customer data (your data) over multiple global regions/territories).

We explore how to over come this very present danger to personal or sensitive corporate data.



CHALLENGES

Cloud solutions are supposed to be about freedom and business enablement, but regulatory compliance, laws for data protection and companies wanting to keep control of their data mean you have to look more carefully where your data resides.

Government agencies and lots of companies across assorted industries with vested interests in data security and mandatory compliance, want to control where their data is stored, so that they do not become exposed to regional laws for data access in other countries.



Never-­ending stories of data breaches focus the mind on security


High profile data breaches illustrate how easy it is to lose control over information. Examples of hacks and data leaks, major email and social media platforms, banks, financial companies, media, governments…to be honest the list is endless.


This does not mean you should place a cross instead of a tick beside cloud computing, it simply means that the security consideration requires extra attention to assess and decide how to mitigate the associated risk.


 

Solutions exist to remove this risk from the equation


Where is your data? Your data may not be hosted where you think



Many of the current concerns that surround data sovereignty relate to enforcing privacy regulations and preventing data that is stored in a foreign country from being subpoenaed / witness summonsed by the host country’s government. To us that is a bit of an after thought by the organisations giving concern - it seems so many businesses were keen to adopt new technology and services in the name of competitive advantage and profit, without considering the long term dangers, or were perhaps never informed about the legal implications at the time.


 

Has your sensitive data left the country or been shared with unauthorised people?


Not only is there a chance that data is unwittingly being stored outside the corporate network, on servers outside the country of your legal data protection, and file being shared amongst work colleagues or supplier partners without your knowing, but you have to beware and track data in cloud application services your business as agreed and subscribed to using. Do you use any of the following, or ones like them?



Mobility and the roaming workforce

Controlling where your data is stored has become increasingly difficult, mainly because of the break down of the network 'edge', and increasing accessibility by users on mobile devices (BYOD) - taking data off the network, where once the only people who accessed files came into an office to use a desktop computer or a few mobile sales people who only had access via a corporate owned laptop.

In the light of cloud computing, work force mobility and BYOD, organisations are faced with the struggle of making data available, protecting intellectual property on the move and meeting regulatory compliance for data protection. Organisations ideally want data to reside within specific geographic / legally protected locations, but also want to meet the needs of a global roaming work force or customer base, service availability, address rapid backup and recovery of critical systems.


Shadow IT  -  BYOD  -  File Sharing



Internet based cloud apps and on device backup options were already being offered to people for free, built into new smartphone and tablet devices that flooded into the market, sold to everyone as a way to be 'always connected' for email, social media and shopping.

The business sector however, were still busy weighing up the benefits, deciding business policies and cost of adopting cloud. Touted as cutting the on-going costs of IT infrastructure and offering unlimited computing resources, storage and service availability for a global workforce or market place - somehow the detailed consideration for securing data got overlooked or pushed to one side with the mentality of what can we get away with as minimal risk if something goes wrong. As we all now know, the what if factor rears its head too often with data loss and breaches all over the news - organisations seemingly have lost control over their data.

A growing global workforce and the need to collaborate and share data with third parties, customers and partners added to this complexity. Users automatically and increasingly turned to unsecure (shadow IT options), consumer-style cloud services as a quick fix / go between for access to their data and files across all of their devices, as well as the ability to share those files with others.

Employees now have access to both your corporate network and personal cloud services from a single or personally owned device(s). (Businesses can be forgiven for allowing this BYOD trend, as employees working from anywhere at anytime has its productivity advantages).

Some users might think the file they have accessed (downloaded as PDF or draft document / email) from work is only stored on their smartphone or tablet - wrong. Often service providers like Google Android automatically backup or guide you to store files on their cloud servers - seamlessly without you really having to do anything. Sold to consumers as being able to 'sync and share' with your other devices easily, or file recovery in the event of device loss....which is all very well if you lose your device (but people rarely read the terms and conditions for data storage and retention). Little thought is given to where company files/personal information is ending up - food for thought.

If unregulated, corporate data can be sent from a personal mobile device via email, social media messaging or stored and shared with anyone via third party 'convenience' cloud sites like Dropbox, Google, Outlook.

These service providers have data centres across the world - where often your data is stored or replicated to servers in the US or Europe...not necessarily in UK where you might be standing. The point being, once a copy of your data/file lands on the soil of another country with different jurisdictional rules and laws about viewing peoples data - there is very little you can do to stop access if they really wanted it (government agencies have collaborated / forced these and other service providers to grant access to data for mining / intelligence - highlighting how vulnerable your personal data is when on a foreign, legal / jurisdictional location).

Lets be honest, nearly everything you send, store or share is in open, raw data format - how many of you are encrypting all the data you send or store? For most of us the answer is no because either we don't know how to, cost prohibitive to implement, or we might only be encrypting data at rest and not during creation and in transit.
 


Its not always malicious - these systems are setup this way to go round our eyes.



Your data in the cloud


Do not just associate sensitive data as being documents. Any form of data is intellectual property from your organisation...
The modern corporation generates a plethora of digital files, all of which are now candidates for, or generated by, cloud storage. For example:
  • Imaged versions of original paper documents
  • Files (including word processing, spreadsheets, presentations)
  • Email (including email messages, instant messages, logs and data stores)
  • Databases (including records, indices, logs and files)
  • Logs (including accesses to a network, application or Web server, customer tracking or profiling)
  • Transaction records (including, in particular, financial records)
  • Other forms of meta-­data
  • Web pages (whether static or dynamically constituted)
  • Audio and video recordings and streams
  • Applications data sets
  • Software itself may constitute a significant cloud data holding
  • Access control information and passwords
  • And many others too …



Compliance


Corporate policies and government/sector-based compliance regulations have understood these risks for years and have set out rules and guidelines for businesses to adhere to and follow, such as PCI DSS, HIPAA, GLBA, CJIS and ITAR  - they place restrictions on how sensitive data is managed in cloud environments.

Cloud compliance and cloud data privacy issues, along with regulations that govern the physical location of sensitive data (known as cloud data residency regulations), often determine the degree to which you can truly realise the value of cloud computing.


Since the PCI DSS guidelines implement common security best practices they are a good jumping off point for evaluating the security of any application and platform.


In summary, they suggest segmentation within cloud-computing infrastructure by isolating at the network, operating system, and application layers.
Proper segmentation is difficult to achieve even when you do not have complete control over all aspects of your environment. When you add the inherently shared and multi-tenant architecture of cloud platforms this becomes a more difficult goal to achieve.

“Client environments must be isolated from each other such that they can be considered separately managed entities with no connectivity between them. Any systems or components shared by the client environments, including the hypervisor and underlying systems, must not provide an access path between environments.”


The PCI guidance tells us what this segmentation looks like in a cloud environment:

A segmented cloud environment exists when the cloud service provider enforces isolation between client environments. Examples of how segmentation may be provided in shared cloud environments include, but are not limited to:

  • Traditional Application Service Provider (ASP) model, where physically separate servers are provided for each client’s cardholder data environment.
  • Virtualised servers that are individually dedicated to a particular client, including any virtualised disks such as SAN, NAS or virtual database servers.
  • Environments where clients run their applications in separate logical partitions using separate database management system images and do not share disk storage or other resources.
Does your cloud service provider implement any of the services that meet these basic requirements?

In an ideal world, you'd like the answer to be yes. But I bet if put under the microscope, the reality is NO. The above requirements are a big ask, and if truly implemented, would be an expensive deployment - perhaps hence why it is imposed on the financial services industry - those that can afford it - but this is not a practical or cost effect model for everyone else.

The point is, the only absolute assurance you have the systems and measures are in place, are that if you are the one implementing them and can see them for yourself at any time. Can we really rely on third parties with data centres in far geographical locations to guarantee these measure 100%?


Who is responsible


Data sovereignty analysis is not limited to the CIO. Legal counsel, finance/treasury, information technology security, corporate audit, procurement and risk managers, among others, need to implement responsible corporate governance and risk management practices, which are essential for companies using a cloud infrastructure. Businesses must balance the flexibility and potential cost savings of cloud computing with the risks inherent in storing data off-­site, beyond the company’s direct control, and possibly even in a foreign country with different laws.



SOLUTIONS



How to protect data and information, not only in your key business applications / services - but everywhere?


SecureNet Consulting cares about data protection - we manage a portfolio of solutions you should implement if you are serious about data protection, and not just because of compliance - but for best practise and corporate due diligence and responsibility.




Do you have a policy? 


Many organisations don’t have an adequate policy in this area.

Their existing document or data management policies may not cover jurisdiction or location, nor recognise challenges thrown up by hybridising cloud services with your private network environment. A few but not conclusive question to ask yourself:

Q: Do you have a clear policy for digital document retention and destruction in the context of the cloud?

Q: Do you have the means to enforce your policies?

Q: Specialists tasked to implement and maintain such policies and protocols?

Q: Plan to 'discover - eDiscovery' over all your cloud-­hosted data, and to protect certain elements of it from unwarranted access?


If the answers to some of these questions is 'no', then all is not lost. While you still iron out process and red tape, technology can plug the gaps and in many case already address all the data protection and compliance concerns.

We outline the individual controls you can put in place to secure data in the cloud. Addressing the increasingly on-demand, access-anywhere environment, organisations are looking for ways to provide employees, partners and other third-parties with access to information, while at the same time protecting that same information from falling into the wrong hands. 

It is however recommended to embrace a combined approach (compliance, audit, visibility, data-centric protection, access control and data management).



Centralise Data Access & User Rights

It is possible to protect all your data where ever it is – where ever it travels: Anytime – Anywhere protection 

The key here is to focus in and secure the one thing we all want to protect - the 'data'.

Until recently, there haven't been many ways to control protect the follow of sensitive data, track it, and who has access and who it is being shared with.

Different solutions vendors approach this challenge and solution in different ways, often only addressing one piece of the protection puzzle, but their are vendors who have cracked the problem, in a very simple way - ensuring data is classified, secure no matter where it travels or is stored (data level encryption provides segmentation if data or file stored on a mobile device on cloud data server), identity-based access control prevents unauthorised users from accessing the content - whilst providing administrators and/or executives a full audit trial of data and user activity (in the event someone really tries to exflitrate data).




File Sharing 

Corporate / enterprise solutions that enable the integration and control of third party / shadow IT cloud-based services like Google, DropBox, Outlook, Box etc...

These platforms enable the business to white label brand a landing page for mobile device users, controlling what apps can be used whilst on the network and where data can be saved. If data is to be stored for sharing purposes on a corporate brand DropBox with a partner or supplier (perhaps because neither of them are allowed direct access to the network and servers). The DropBox is actually a containerised version of the consumer version...meaning that once the user leaves the network or time has lapsed, then the file if no longer accessible.
The business can track if file reside on or off the network and remote delete if needed.


Data Centre Services

Choose a datacentre service provider that won't store your data outside your jurisdictional area.

SecureNet Consulting is partnered with leading data centre service providers that offer both coverage in international locations - addressing both your needs for geographical and data sovereignty considerations. These data centres can be used either as primary operation bases, secondary off-site locations or data backup repository site for recovery or testing requirements. These service provider may provide extended cyber security and data protection services (encryption) – depending on the provider and service package. The controls and solutions offered below may be optional extras from the service provider, otherwise these are technologies you can invest in.

  • U.S.
  • U.K.
  • South Africa
  • Singapore
  • Off Shore Locations


Data Management

Data management encapsulates the management of every aspect of data and its life-cycle, for example, creation, classification, retention, archiving, backup and storage locations, replication, version controls search and eDiscovery...to name but a few.
Traditionally many organisations have seperate tools in place (perhaps open source or cheap software) that in this day and age are really not equiped to factor in and properly control where and how data travels.
Choose a data management platform that truely allow you to centrally manage all your data - solution exit to ease and make data management much more cost effective long term, rather than battling with old systems that have limited functionality.

Data management / backup and recovery solution providers enable you to control where your on-premise data is backed up – be it an off-site private cloud / DR site or cloud based service by a third party provider.

Encryption is often now built into the solution, at rest, which goes with the data when in transit to other destinations.


Data Backup

Solution vendors still focusing on helping medium and small business address data protection with next-generation data backup and recovery, have done very well to provide enterprise control over where your data is being backed up, replicated or migrated.


Encryption

Take control of the encryption process. Encrypting data renders it useless to people who do not have the keys.
  • Encrypt data in transit from the cloud through authorised applications to endpoint / mobile devices. Ideally data remain encrypted on devices and controls are applied to prevent that data being copied anywhere other than authorised / specified by policy. 
  • Encrypt data at rest / storage with their own encryption keys.


Data Segmentation 

Achieved through encrypting data and managing user access rights, outside of the cloud data centre administrators.
 


Tokenization

Can be used to keep sensitive data local (resident) while tokens (replacement data) are stored and processed in the cloud / foreign data centres. 

Assures compliance with regional data residency laws while preserving the intended application functionality.


Data loss prevention (DLP)

DLP software defines controls over the flow of data and monitors that data flow to detect data breaches. 
 



eDiscovery & Data Classification

Find and identity your sensitive data wherever it may reside (desktops, mobile devices, cloud storage locations). Encryption, policy rules and data loss prevention controls can be put in place.
 


Audit

Continually report and review the security and policy controls are in place and working. Monitor and report on user activity: accessing sharing, editing sensitive documents. 
 


Data Policy Management (retention)  

Your legal department can outline how long legal files should be stored, archived, before deletion. 




Risk Mitigation – tips for CIOs  

While cloud services can result in users losing control over how and where data is stored, CIO’s can fortunately play a proactive role in partnering with risk management and legal to set up risk mitigation and transfer policies designed to address and limit not only the incidence, but also the most severe adverse consequences, of cloud computing data sovereignty risks.

Some of the common ways this can be done include:
 

IT Use Policy Review: Audit and regularly review your reliance on different forms of technology (i.e. Cloud Computing, smartphones, iPads, USBs) and ensure that various uses of such technology (i.e. work, social media, personal use) are appropriately regulated in company IT and/or Social Media policies and guidelines.

Supplier Audit: Identify any organisational dependence on outsourced service providers (especially cloud service providers) and work with the IT Security and Risk Management Department to perform regular and systematic audits of third party security infrastructure and practices designed to protect against data sovereignty risks, unauthorised access, use and disclosure of confidential information. Ensure that you have transparency of downstream level providers.


Training: Educate everyone regarding the evolving legal exposures for both companies and individuals where it has been found that there has been a serious or repeated breach of privacy under the Data Protection Act.

Contracts: Mitigate cyber exposures by developing consistent contractual allocation of liability templates in both customer and supplier contracts which place obligations on contractual parties to satisfy the minimum data collection, use, disclosure, and security requirements under the Privacy Reform Act.

Data Breach Management: Consider the benefits of implementing a Data Breach Management Policy to address and outline internal corporate prevention, detection and incident response processes in response to a security breach. It could help in defending an allegation that the company failed to take reasonable care in handling a data security breach.
 


Cyber Liability Insurance: Analyse your property and general liability insurance policies and determine any potential gaps in existing coverage. You may want to consider specific Cyber Liability Insurance to fill any obvious gaps.






Contact us today to discuss your requirements in more detail.



Telephone 
+44(0)7714 209927
+44(0)1273 329753
http://eepurl.com/GKx25

info@securenetconsulting.co.uk

Email                            
https://www.linkedin.com/in/paul-rummery-0b89535

https://plus.google.com/116898209106255177774

http://www.fhttps/www.facebook.com/pages/SecureNet-Consulting/188102854572105