Minimizing PII Exposure and Loss Minnesota

The government has always gone to extraordinary lengths to protect classified data and trade secrets. However, much of the information that is deemed “unclassified data,” such as names, Social Security numbers, birth dates and other forms of Personally Identifiable Information (PII), are also in dire need of stringent security controls.

The shift to e-government -- and all that comes with it, including high-speed networks, mobile computing and better information sharing -- has introduced new risks to PII. At the same time, agencies are being held more accountable for IT security measures, and PII is becoming more valuable to criminals, making the protection of PII a top priority for government officials.

This article provides a look at PII within government, where it’s vulnerable, and steps that can be taken to keep it safe.

Local Companies

Olson & Co
(612) 215-9800
1625 Hennepin Ave
Minneapolis, MN
National Association of Credit Management
(612) 341-9600
1201 Marquette Ave
Minneapolis, MN
Infosource
(612) 338-4118
420 N 5th St
Minneapolis, MN
Siebell Management Consultants
(651) 998-0488
2865 Neal Ave S
Afton, MN
Wilkinson Project Group Ltd
(952) 931-2123
11661 Vista Dr
Minnetonka, MN
Decision Intelligence Inc
(952) 653-0980
5900 Rowland Rd
Hopkins, MN
Cook Inc District Manager
(507) 282-0041
Rochester, MN
International Jet Inc
(612) 726-5775
3650 E 70th St
Minneapolis, MN
Davis Brent Llc
(952) 746-1601
904 Mainstreet
Hopkins, MN
Horizon Management Llc
(763) 546-1336
3539 Douglas Dr N
Minneapolis, MN

Minimizing PII Exposure and Loss



By Stacey McDaniel

The government has always gone to extraordinary lengths to protect classified data and trade secrets. However, much of the information that is deemed “unclassified data,” such as names, Social Security numbers, birth dates and other forms of Personally Identifiable Information (PII), are also in dire need of stringent security controls.

The shift to e-government -- and all that comes with it, including high-speed networks, mobile computing and better information sharing -- has introduced new risks to PII. At the same time, agencies are being held more accountable for IT security measures, and PII is becoming more valuable to criminals, making the protection of PII a top priority for government officials.

This article provides a look at PII within government, where it’s vulnerable, and steps that can be taken to keep it safe.

Reporting breaches
A July 2006 Office of Management and Budget memo requiring agencies to report all breaches involving PII within one hour of discovery has helped the government realize just how prevalent this issue is. In June 2007, 40 agencies reported an average of 14 incidents that involved exposure of an American’s PII each day. By October 2007, the same agencies were reporting an average of 30 incidents a day. Even though many of the incidents have relatively harmless consequences, agencies can’t afford to take any risks.

Within any government agency, PII is at the fingertips of every staff member who has email, database and Web access at work. The growing use of removable media such as USB drives, CDs/DVDs and portable Mp3 players brings new risk into the picture by making PII easily transportable on devices that aren’t always properly secured.

Here are the most common ways PII can become exposed:

  • Device theft or loss According to a 2007 study by the Ponemon Institute, lost or stolen laptops and other devices such as removable drives accounted for almost half of data breach incidents (49%). A widely publicized theft occurred in May 2006, when a Veterans Affairs employee’s laptop and external hard drives containing digitized records of active-duty troops and veterans was stolen from his home. In another case, a recent review performed by the Commerce Department stated that more than 1,100 of the Department’s laptops have either gone missing or been stolen over the past five years.
  • Database break-in/hacking Criminals are constantly developing new malware, worms and spam to access confidential information for monetary gain. For example, in late October 2007, an Oak Ridge National Laboratory database was penetrated through several waves of phishing email messages. Once inside, the attackers accessed the names, Social Security numbers and birth dates of lab visitors between 1990 and 2004.
  • Insider threat Disgruntled employees seeking revenge or inadvertent human error are to blame for a number of breaches that occur from inside the network. One example: In January 2007, an employee at the Los Alamos National Laboratory unintentionally transferred sensitive information through an unsecured email system.

Protection measures
Government agencies should first minimize the amount of PII that they collect and store. Following that, PII access should be limited to a need-to-know basis. Encryption, strong authentication procedures and other security controls can all make PII unusable by unauthorized individuals. Here’s a closer look:

  • Discovery An agency cannot protect what it cannot find, so it must first identify the PII it has and where it is stored. File servers, databases, desktops, laptops, remote devices and all other data repositories should be scoured for PII. There are solutions available that not only scan for this information but also address any exposed data on the spot.
  • Access control Agencies face similar problems with data usage. Since they do not always know how PII is being used, it is hard to manage it. Mobile endpoints present an even bigger challenge, because it is difficult to track which laptops and devices hold PII, and why it is being exchanged between devices. A solution should be in place to monitor activity and prevent PII from exiting any network gateway or endpoint.
  • Encryption Because device theft and loss is the No. 1 reason for PII exposure, encryption is the best way to ensure that data is useless to criminals. PII contained in databases or stored on mobile computing devices such as laptops, PDAs, CDs or drives should always be encrypted.
  • Education In addition to technical safeguards, employees should be made aware of data security issues and advised to be on the lookout for suspicious activity. Employees will recognize that there are new authentication measures in place, so the best thing to do is educate them on why securing PII is so crucial, as they are an important line of defense.

Conclusion
Today, the government is responsible for storing and managing a staggering amount of PII, the volumes of which continue to grow. All that data must be protected from threats from both inside and outside the network.

 

Stacey McDaniel has been writing about high-tech issues for more than six years.

Featured National Company

Epik Networks

604-282-4690
890 - 789 West Pender Street
Seattle, WA
www.epiknetworks.com

Regional Articles
- Minimizing PII Exposure and Loss Albert Lea MN
- Minimizing PII Exposure and Loss Andover MN
- Minimizing PII Exposure and Loss Anoka MN
- Minimizing PII Exposure and Loss Bemidji MN
- Minimizing PII Exposure and Loss Brainerd MN
- Minimizing PII Exposure and Loss Burnsville MN
- Minimizing PII Exposure and Loss Champlin MN
- Minimizing PII Exposure and Loss Chanhassen MN
- Minimizing PII Exposure and Loss Chaska MN
- Minimizing PII Exposure and Loss Circle Pines MN
- Minimizing PII Exposure and Loss Cloquet MN
- Minimizing PII Exposure and Loss Cottage Grove MN
- Minimizing PII Exposure and Loss Detroit Lakes MN
- Minimizing PII Exposure and Loss Duluth MN
- Minimizing PII Exposure and Loss Eden Prairie MN
- Minimizing PII Exposure and Loss Elk River MN
- Minimizing PII Exposure and Loss Excelsior MN
- Minimizing PII Exposure and Loss Faribault MN
- Minimizing PII Exposure and Loss Fergus Falls MN
- Minimizing PII Exposure and Loss Forest Lake MN
- Minimizing PII Exposure and Loss Hastings MN
- Minimizing PII Exposure and Loss Hibbing MN
- Minimizing PII Exposure and Loss Hopkins MN
- Minimizing PII Exposure and Loss Inver Grove Heights MN
- Minimizing PII Exposure and Loss Lakeville MN
- Minimizing PII Exposure and Loss Mankato MN
- Minimizing PII Exposure and Loss Minneapolis MN
- Minimizing PII Exposure and Loss Minnetonka MN
- Minimizing PII Exposure and Loss Moorhead MN
- Minimizing PII Exposure and Loss Mound MN
- Minimizing PII Exposure and Loss New Ulm MN
- Minimizing PII Exposure and Loss Osseo MN
- Minimizing PII Exposure and Loss Owatonna MN
- Minimizing PII Exposure and Loss Prior Lake MN
- Minimizing PII Exposure and Loss Red Wing MN
- Minimizing PII Exposure and Loss Rochester MN
- Minimizing PII Exposure and Loss Rosemount MN
- Minimizing PII Exposure and Loss Saint Cloud MN
- Minimizing PII Exposure and Loss Saint Paul MN
- Minimizing PII Exposure and Loss Savage MN
- Minimizing PII Exposure and Loss Shakopee MN
- Minimizing PII Exposure and Loss South Saint Paul MN
- Minimizing PII Exposure and Loss Stillwater MN
- Minimizing PII Exposure and Loss Wayzata MN
- Minimizing PII Exposure and Loss Willmar MN
- Minimizing PII Exposure and Loss Winona MN
Rate Article
     
Articles Insider

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Software
Business Services Fashion Internet Technology
Career Financial Services Legal Telecommunications
Cars Franchise Miscellaneous Trade Shows
Computer Hardware Health Nightlife Travel
Construction Holidays Online Database Weddings
Education Home Appliances Pets World History
Entertainment Home Electronics Real Estate Resources