ClearCrypt Data Loss Prevention Best Practices
At ClearCrypt we recognise that there is still a use for portable storage devices, even though access to cloud storage via WiFi, 4G, and increasingly 5G, are widespread within Ireland and the UK. We have covered why it is still a good idea to allow staff to use USB storage devices and why those USB storage devices should use hardware encryption, particularly in this era of GDPR and other regulatory frameworks.
ClearCrypt hardware-encrypted USB storage devices offer the best in class features for providing secure mobile storage. The main reason to use our secure storage is to prevent data loss if a device is lost or stolen. The need to enter a unique PIN directly on each device when mounted for reading and writing on a computer means that the encrypted data is secured even if a passer-by rips a USB device from a laptop. The articles linked above go into more detail on the ClearCrypt device features. In this article, we will highlight some general best practices that organisations should consider to ensure they have a data loss prevention (DLP) policy in place.
Data Loss Prevention (DLP) Policy
A single organisational wide DLP policy that all departments and staff are on-board with is the primary best practice for DLP. This policy should explain the different classifications of data that are used within the organisation, and what level of security is required for each. It should also outline how data should be protected when used in these three scenarios:
- Endpoint - when data is used on devices like PC’s, Macs, tablets, smartphones, and via web apps from private and public computers.
- Network transit - ensure that any data sent over the network is encrypted. For example, making sure to check for secure connections in web browsers.
- Storage - make sure the data saved to any device, a network store, or a portable storage device is encrypted. ClearCrypt devices ensure the latter use is secured at all times.
Most of these will be the responsibility of whoever is in charge of IT within an organisation, or their designated external IT supplier. Many IT suppliers will have a DLP policy that can be amended and adopted by most organisations to ensure that users know what to look for to ensure the data they use and save is secured. Knowing what to look for makes the next point vital.
User Training
Training users is a best practice and a vital part of any DLP policy and action plan. Training them to identify when connections to web sites are not secure, and making sure they know what to do rather than continue to enter data, is critical. As is making sure that they never use USB storage devices that are not hardware encrypted to save and transport data.
Increasingly web sites are using secure connections, so training users to spot the tell-tale signs in a web browser for a website that is not secure is probably better than making them check for a secure connection. The exceptions will stand out as they will be rare. Making sure there is a defined path to follow to get help is also vital.
Create a Culture of Openness
DLP requires both IT tools to secure data and a culture of openness and discussion within organisations. Everyone should feel free to raise any concerns or doubt they have without being made to feel embarrassed. Especially concerning data security. No question is a stupid question in this area. Easy and rapid access to security experts should be provided so that any doubts can be raised and dealt with in real time. An excellent way to deliver this is via a messaging system such as Microsoft Teams or Slack chat.
Only Store Data That is Needed
It might seem obvious, but it is worth pointing out that only data that is needed should be stored and transported. Data that is not on a USB device or is not transmitted over the network can’t be accidentally lost or stolen. So any DLP policy should include a best practice provision to archive or delete older data so that it is not just sitting on devices and network stores when it doesn’t need to be there.
Document Any Incidents
Accidents will happen, as will activities such as phishing attempts. A DLP policy should document how any incidents that occur should be recorded. It should also include provisions for frequent review of any events and also reporting of these to Executives. This reporting should consist of the incident type, whether any data was lost, what the impact was, and what steps have been taken to prevent it from happening again in future. Trends over time should also be reported to highlight anything that points to the need for additional training or new procedures.
Conclusion
There is no single thing that will ensure DLP. Security tools and best practice behaviours across organisations that work in concert are needed. ClearCrypt’s USB storage devices deliver a hardware-encrypted component that can plug-in and provide secure storage for users who want to use mobile storage. For the other security components needed to provide comprehensive DLP, then Renaissance and our partners have all the tools and consulting experience any organisation would need to ensure DLP best practices are delivered.