About Me

Evan Schuman

Evan Schuman
Founder and Editor-in-Chief
StorefrontBacktalk.com

Evan Schuman is founder and editor-in-chief ...

Read More

Feeds & Podcasts

Enterprise Blogs

Meet the Bloggers

Archive

Tags

#McAfeeFOCUS, #MFETrivia, #SecChat, 12 Scams of Christmas, 2012, 2012 Security Predictions, Acquisition, Advanced Persistent Threat, Android, Android Malware, anti-virus, antivirus, App Alert, Apple, application developers, application security, apps, app safety, ATM scams, attacks, automotive, Bad Apps, balanced scorecard, best practices, BlackBerry, Black Hat, Blackhat, black hat hackers, botnet, breach, car hacking, certification, China, CISO Executive Summit, Citrix, class action lawsuit, cloud, Cloud city, Cloud computing, Cloud Expo, cloud security, Cofer Black, Compliance, Conficker, consolidation, Consumer, consumerization of IT, Content Protection, counter identity theft, credit card fraud and protection, critical infrastructure, CSP, cyber attack, Cybercrime, cyberespionage, Cyber Insurance, Cyber Intelligence Sharing and Protection Act of 2011, cybersecurity, cyber security, cyber security awareness, Cyber Security Mom, cyber threat, cyberthreats, data, database activity monitoring, database security, data breach, Datacenter, data center, data center security, Data Classification, data loss, Data Protection, Dave DeWalt, Dave Marcus, dedicated security appliances, Deep Command, Deep Defender, DeepSAFE, DefCon, DefCon Kids, Department of Commerce, device, Device Control, devices, DLP, Dmitri Alperovitch, easter, Eelectric Vehicle, Email & Web Security, Email & Web Security, embedded, embedded devices, Embedded Security, encryption, Endpoint Protection, enterprise, enterprise mobility, enterprise resource planning, enterprise scurity, enterprise security, epo, ePolicy Orchestrator, ERP, espionage, EV, exploit, exploits, facebook, Facial recongnition, Family Safety, FDCC, FISMA, Fixed Function Devices, Focus, Focus11, FOCUS 2011, forrester, Foundstone, Friday Security Highlights, Gartner, Gartner Security and Risk Management Summit, George Kurtz, Global Cybersecurity, Global SecurityAlliance Partner Summit, global threat intelligence, google, government, GTI, Hackers, hacking, Hacking Exposed, Hacktivism, HB1140, Healthcare, Heuristics, HIPAA, host intrusion prevention, Host IPS, HV, Hybrid Vehicle, ICS, identify potential cyber-threats, identity protection, identity theft, IDF 2011, Information leak, Information Protection, Information Security, Insider Threats, Integrity, intel, intellectual property, Internet Explorer, Interop, IntruShield, In vehicle Infotainment, IP, iPad, iphone, IPS, IT, IT Security, japan earthquake safe donation, japan earthquake scams, laptops, Larry Ponemon, law, legal, legal risk, live-tweeting, lizamoon, Lockheed Martin, mac, Mac OS X, malware, Malware research, managed security services, Management, Mariposa, mass sql injection, mastercard, Maturity Model, McAfee, McAfee Application Control, McAfee Cloud Security Platform, McAfee Data Loss Prevention, McAfee Email Gateway 7.0, McAfee ePO, McAfee ePolicy Orchestrator, McAfee Firewall Enterprise, McAfee FOCUS, McAfee FOCUS 2011, McAfee Identity Protection, McAfee Labs, McAfee Mobile Security, McAfee MOVE AV, McAfee Network Security Platform, McAfee NSP, McAfee Policy Auditor, McAfee Risk Advisor, McAfee Security Journal, McAfee Security Management, McAfee Security Webinars, McAfee Vulnerability Manager, McAfee Vulnerability Manager for Databases, mcafee wavesecure, Microsoft, Mid-Market, Mobile, mobile data communications, mobile device, mobile devices, mobile devices and security threats, mobile malware, mobile phone spyware, mobile security, mobile smartphone security, mobiles security, mom, NAC, near field communication, Network Security, Network Security; Email & Web Security; Security-as-a-Service, network security server security, new year resolution, NFC, Night Dragon, NitroSecurity, OMB, online banking, Open Source, operational risk, Operation Aurora, Optimized, outages, OWASP, passwords, password security, patch, Patch Tuesday, Patmos, PCI, PCI Compliance, PCI DSS, perception, personal information over mobile phones, phishing, PII, Ponemon Institute, PostScript, Potentially unwanted program, power grid, power loss, Pre-detection, Printers, privacy, protection, Public-Private partnerships, Public Sector, pup, reference architecture, regulations, reporting, reputational risk, retail, risk, Risk Advisor, Risk and Compliance, Risk Management, ROI, Rookits, Rootkits, RSA, SaaS, Saviynt Access Manager, SCADA, scam, SCAP, SEC Guidance, SecTor, security, Security-as-a-Service, Security and Defense Agenda, security awareness, security breach, security conferences, Security Connected, Security Connected Reference Architecture, security management, security metrics, security optimization, security policy, Sentrigo acquisition, Shady RAT, SharePoint, shortened URLs, SIA Partners, SIEM, SiteAdvisor, Small Business, smartphones, smartphone security, SMB, social business, social media, social networks, Software-as-a-Service, spam, Spearphishing, sql attacks, SQL Injection, stealth attack, stealth crimeware, stealth detection, Steve Jobs, storage, Stuxnet, Support, Symbian, T-Mobile, Tablet, tablets, targeted attacks, TCO, technology development, Telecommunications, threat reduction, TJX, TPM, Trusted Computing Module, trustedsource, twitter, Twitter online security, U.S. Cyber Challenge Camps, urchin.js, Vericept DLP, ViaForensics, Virtualization, VIrtual Machines, visa, Vontu DLP, vulnerability, Vulnerability Manager, vulnerability manager for databases, Web 2.0, web security, Websense DSS, Web services, white hat hackers, Whitelisting, wikileaks, Windows 7, Windows Mobile, Wind River, Xerox, youtube, Zero-Day, zeus

It's Not Just For Card Data Any More

Wednesday, November 11, 2009 at 6:09pm by Evan Schuman
Evan Schuman

With all of the recent fuss about PCI requirements and how to protect payment cards, many companies have opted to take a far too narrow view of data protection. The PCI rules are absolutely designed to only apply to payment cards, but the same common-sense security guidelines will also dramatically help the security of CRM databases, personnel files, E-mail servers, payroll details, and even the full contents of your Web site.

Overworked IT executives suffering from staff cuts find checklist security quite comforting. The checklist mentality says that nothing should be done that isn’t mandated. And there are no external rules protecting data, beyond payment card, health-related information and some investment data. Is this wise?

This month, a frightening answer to that question came in the form of an E-mail exchange that a reader enjoyed. The reader—a security consultant—got a panicked call seeking a forensic expert. A large amount of important data had been stolen and they hadn’t been doing backups of that content. Even worse, they couldn’t even try and piece together what the intruders had stolen because of a logging problem. To quote the victim: “We can’t recover it, because it’s wasn’t backed up, and it wasn’t logging because it wasn’t on the part of the SAN where logging occurs.” Uh-oh.

Our reader said that he figured the data couldn’t have been close to mission-critical, given the cavalier way it was protected. But the victim had an interesting rationale: “Well, it wasn’t part of PCI so we didn’t think to add it into the normal data we monitor” with several different high-end security packages. The kicker: Why was the victim so desperate to retrieve this non-PCI-controlled data? “It’s the flight maintenance records for our entire fleet of aircraft.”

While this executive’s company’s safety details were off somewhere in the wild blue yonder atop CyberThiefVille, his counterparts were calmly deciding that security procedures should be minimalized.

If a thief wants to engage in identity theft, there are plenty of nuggets of data far more valuable than payment card information. Worried about an inside job? Wouldn’t the payroll database be a more tempting target?

Retailers today are amassing more data about Americans than anyone other than U.S. government. If retailers ever get their mouse pads around all of the data they’re already collecting, the image is staggering. For loyalty card using consumers, the chains know what they’ve bought and when. Courtesy of E-Commerce tracking, they know what they thought about buying, but chose not do. If stores truly deploy item-level RFID tracking, that knowledge will be known in-store, too. How would you like your next potential employer to be able to read a transcript of every question you’ve ever asked a customer service or tech support person?

That’s all data that’s being collected today. Some retailers are considering some even more Orwellian possibilities for next year

This all comes down to the fact that businesses of all sorts—and especially retailers—are collecting a lot of data today that no outside force is requiring them to protect in any formalized way. That means that companies must decide—on their own—to spend money and dedicate personnel to protect systems that they don’t technically have to. These execs will either do the right thing or face data Armageddon. Excuse me while I go out and buy a generator and a 30-year-old supply of survival supplies.

Evan Schuman is a guest blogger on the McAfee Security Insights blog. Evan is the founder and Editor-in-Chief of StorefrontBacktalk.com, a global site that tracks retail IT and E-Commerce issues for readers. He also writes the weekly Retail Realities column for CBSNews.com. More on Evan can be read on his author page.

Bookmark and Share

Tags: , , , , ,

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (0)