The Oracle Australia and New Zealand Middleware and Technology Blog.
Showing posts with label Data Privacy. Show all posts
Showing posts with label Data Privacy. Show all posts

Monday, August 18, 2008

Have you ignored PCI


Think about who has your credit card details, when you look at your household dealings they include council, electricity, gas, water, building insurance, car insurance, petrol and it goes on. I am sure all of us have at least 50 relationships with various organisations via consumer spending with credit cards. In fact it would be greater when you factor in frequent purchases like clothing. When you consider the rapid growth of internet espionage, fraud and identity theft what is being done to protect us. PCI is the best example of legislation that is designed to protect the mums and dads.

The PCI Data Security Standard is nothing new; it has been around for a few years and depending on the region it can be front of mind or ignored. In the land of compliance (USA) of course PCI has seen heavy adoption, but in Asia Pacific the adoption has been lagging.

So what is PCI, well to put it simply the card merchants AMEX, Diners, Visa, JCB and Mastercard came up with a set of recommendations or best practices for any organisation that deals with credit card data. For example encrypting card numbers or making sure your systems are patched to the current versions so they are less succeptable to hacking are examples of these recomendations. There are 12 in total, and on reviewing them you have to wonder why they wouldn’t be adopted. It just makes good sense.

That’s clearly the problem, when does “good sense” make a good business plan. Rarely if at all is my opinion. With the IT industry unable to propose anything it seems unless tied to an ROI, TCO, SLA or some other acronym, simply put compliance especially in Australia is a tough sell. Where is the pain!

Well the pain is coming, credit vendors currently do fine organisations for failing PCI audits, but the organisation may never suffer the fine. Banks can at their discretion choose to absorb the fine and not pass it onto their customer. If the organisation that has failed the audit has significant financial heft, and hence contributes a large revenue stream the bank would for the sake of the relationship simply eat the fine. But these fines are now becoming more frequent and larger. Plus the smaller Level 2 and 3 merchants are coming under closer scrutiny. So now the banks will be forced through the size and frequency of the fines to start passing more of them onto their customers. This of course is great news for consumers like you and me since we deserve a better deal when it comes to privacy and protection of our financial dealings.

With this changing dynamic of banks pasing down the fines, and the continuous IT mantra of “do more with less” IT automation is coming of age across the board. Most organisations have come to terms with automating employee on boarding or provisioning user accounts, offering self service to change your home address, mobile phone number or a password. So why not automate your compliance regime.

The following deck outlines the 12 guiding principles of PCI and shows how oracle IDM and Database Security solutions can overlay these requirements.

If you would like more information on PCI, and how to start. Give us a call.


Read this document on Scribd: PCI Presentation by Carl Terrantroy

Friday, June 27, 2008

More lost or stolen data

Michael Specht posted an interesting article on his blog regarding the continual problem of organisation loosing sensitive information. I posted a reply outlinning some other challenges around data protection. This is indeed an area where Oracle has a significant value proposition to help protect an organisation.

When you look at where sensitive data resides it often sits on some type of system that has Oracle involvement. Either simple the data may reside on an Oracle database, be access via an Oracle Application or rights granted from Oracle's Identity Management Suite.

So with the complexities of modern enterprise organisations where do you start ?. A good place is the security tool that in a few minutes can give you a high level overveiw on your current data risk. Once you know yor risk it then depends on the individual organisations appetite for risk. Public sector and FSI for instance need to treat data protection and the privacy of their employee's and customers with the utmost respect. While other organisations perhaps in manufacturing dont have the same customer issues since they deal with B2B and hence looking after their own employee's tax file number and bank details could be enough.

Oracle does excel in several significant areas of data protection including Information Rights Management to help lock down sensitive information that could be leaked outside of the firewall. Idnetity Management has an excellent attestation capability to give you an accurate view on who has access to what. Once you know who has access to what Enterprise Role Manager can help you digest and manage the complex relationships between the organisational business roles and IT system levels of privilages access. With IDM and ERM you no have a clear picture of who has access to what. But then due to various access rights and privilage creep you still can benefit from preventative and detective controls to close the loop.

With Datavault protecting your Oracle systems a company can be assured that the super user's are not violating privacy policies by masking or preventing access to sensitive data on the database. Or AuditVault can be used as a method of deploying a secure audit capability that will prove who accessed what critical or confidential peice of information. Auditvault not only looks after Oracle databases that are typically at the core of an organisation but ende databases by other vendors that are typically used at the departmental level and outside of the tight contols associated with a datacenter.

If you or your customer is concerned with privacy, or intellectual propery theft or leakage. Is wondering what the impending eDiscovery legislation means to you or the Privacy Act ammendments then talk to Oracle today.
Cheers
Carl Terrantroy

Friday, May 23, 2008

Oracle Data Security Self Assessment Tool


A simple calculator-style tool to help drive awareness around basic data security issues and Oracle’s Database Security products.

This interactive tool walks the user through key areas of security, then rates the organisation's exposure level and educates how Oracle solutions can address their privacy needs, insider threats, and regulatory compliance challenges.

On the right is a sample graphic from the tool. It takes
approximately 5 minutes to complete.


If you would like to use this tool you can directly access it at http://www.oracle.com/broadband/survey/security/start.html