| 4 keys to EU regulation | |
| “The breach notification requirement places a new burden on data controllers. Under the GDPR, the IT security mantra should always be monitoring” |
Asystec Peter O’ Connor, data governance consultant |
| We, the public, all want to believe that any company or organisation who we disclose our personal information to is doing their upmost to ensure our data doesn’t fall into the wrong hands. These regulations transform that ‘belief’ into an assurance.What can your organisation do, and what should you focus on, in order to adhere to these regulations? Well there are four key areas I would recommend focusing on: Classification, Metadata (retention), Governance and Monitoring. The challenge is tying a number of IT solutions together in order to have at a glance an overview of these four areas. The good news! With a little research you will find there are a few all-encompassing products that cover off all of these areas. We don’t need to re-invent the wheel, the solutions are there!
Here are the four key areas, mentioned above, and a brief explanation of their relevance to the new EU regulations: Metadata – With its requirements for limiting data retention, you’ll need basic information on when the data was collected, why it was collected, and its purpose. Personal data residing in IT systems should be periodically reviewed to see whether it needs to be saved for the future Governance – With data security by design and default the law, companies should focus on data governance basics. For unstructured data, this should include understanding who is accessing personal data in the corporate file system, who should be authorised to access, and limiting file permission based on employees’ actual roles – i.e., role-based access controls. Monitoring –The breach notification requirement places a new burden on data controllers. Under the GDPR, the IT security mantra should “always be monitoring”. You’ll need to spot unusual access patterns against files containing personal, and promptly report an exposure to the local data authority. Failure to do so can lead to enormous fines, particularly for multinationals with large global revenues.
|
|
| Three data questions | |
| “While the new Privacy Shield agreement is being trashed out this provides opportunity for companies to take stock of the current situation, questioning what client data they actually hold and analyse what data is being transferred outside of the EU” |
Viatel Damien McCann, head of marketing and sales |
| As the US and EU place the final touches on the Privacy Shield, which is the successor to the struck down Safe Harbour data transfer agreement, this leaves companies that are sending clients’ personal data from the EU to US in a state of limbo, and potentially breaking the law under the 15-year-old Safe Harbour scheme.Companies need to ask three key questions – Where is our data stored? How is it protected? And are we compliant?
While the new Privacy Shield agreement is being trashed out this provides opportunity for companies to take stock of the current situation, questioning what client data they actually hold and analyse what data is being transferred outside of the EU. Where is this data going? And what are you doing to secure it? Client’s should engage with current cloud providers and request that data is not stored outside of the EU, going forward additional due diligence is needed on the customer side when choosing future cloud platform providers making sure that in a post safe harbour world that you know exactly where data is stored and more importantly how secure it is. Reputable cloud platform providers will happily engage and go the extra mile to address and reassure clients. In Ireland clients will have a number of cloud providers that provide options and guarantees that data is securely stored within the EU or within providing users with options to select the actual primary and backup country for data to be stored.
|
|
| Data compliance journey | |
| “The journey to compliance with the GDPR is not just a matter of paper based policy and procedures but also the utilisation of IT technologies to enforce these policies” |
Triangle Computer Services Donal Byrne, head of automation |
| For many years the subject of securing customer data has been a hot topic in the media. No industry has been left untouched by hackers, leakers or human error leading to the exposure of emails of Hollywood movie studios, customer details of international banks, voter registration details or the user databases of major ecommerce websites. The result of these type of events is usually a trip to the data commissioner within their jurisdiction and a quadruple hit of the remediation of IT security services, reputational damage, revenue loss and, usually, a large fine. These events however have been treated differently from country to country within the EU with differing data protection laws being applied.This has led to the new pan-European law called the General Data Protection Regulation (GDPR) which comes into effect in May 2018 and all companies trading within the EU will have to comply. The GDPR details the requirements for the safe handling of customer data and the penalties for any breaches which can be up to four percent of global revenue for the previous year or €20 million, whichever is the higher. The journey to compliance with the GDPR is not just a matter of paper based policy and procedures but also the utilisation of IT technologies to enforce these policies.
Typically, around 80% of IT security budgets are spent on parameter security devices such as firewalls and data loss prevention (DLP). This usually leaves the internal networks as a free-for-all where the introduction of firewalls and DLP for every server and desktop is operationally complex and highly expensive. With VMware NSX, you can prepare for the GDPR by deploying security controls inside your datacentre network through what is known as the micro-segmentation model. With NSX, security policies can be defined not just in the typical 3-tier manner of Web/App/Database but also down to which individual groups of users or service accounts can connect to particular sensitive IT services. It offers a zero-trust security model inside the datacentre and allows for data-centric adaptive security. Businesses can protect sensitive data processed by their applications and control the security risk level of each workload in real-time.
GDPR does not need to become an obstacle to your business operations and may indeed help bring business value by automating IT security safeguards.
|
|












Ltd