S.C. governor's post-breach data encryption claims are off-base, analysts say
"The governor's comments reflect unawareness of data security practices and are not at all reassuring," Litan added.
Pointing to weak data security practices at banks as a defense for the state's ineptness isn't a good strategy, said Richard Stiennon, a principal at IT-Harvest.
"Critical data, especially personally identifiable information, must be protected and Social Security numbers linked to names, ranks at the top" of the list of items that need to be protected, he said. "Encryption technology is readily available for data stores. It is not cumbersome to encrypt data. To the contrary, it is easy to do and most retailers and payment processors do it regularly."
Some security vendors also took the governor to task for her claims about encryption technology being cumbersome to implement. "Anyone remotely familiar with security best practices knows that all sensitive data should be encrypted," said Torsten George, vice president of worldwide marketing and products for risk management vendor Agiliance.
Typically, the decision not to encrypt sensitive information is driven by budget limitations rather than by industry standards or best practices, George said.
Haley's comments are based on outdated assumptions, said Todd Thiemann, senior director of product marketing at data encryption vendor Vormetric. While encryption technologies used to be somewhat difficult to deploy, these days the technology is not all that complicated, he said.
"Most state data breach laws, including California, Massachusetts and Nevada, call out Social Security numbers as a category of information requiring protection," Thiemann said.
Under most state data breach laws -- including South Carolina's -- encryption provides businesses with safe harbor from notification in the event of a data breach, he noted.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan or subscribe to Jaikumar's RSS feed . His e-mail address is firstname.lastname@example.org.
Read more about Cybercrime and Hacking in Computerworld's Cybercrime and Hacking Topic Center.
- Transforming Information Security: Future-Proofing Processes This report provides a valuable set of recommendations from 19 of the world'd leading security officers to help organizations build security strategies for...
- The Evolution of Corporate Cyberthreats Cybercriminals are creating and deploying new threats every day that are more destructive than ever before. While you may have more people devoted...
- 3 Questions to Ask Your DNS Host about Lowering DDoS Risks Neustar has had wide-ranging conversations with clients wanting to know how they can optimize protection as DDoS attacks increase in frequency and size.
- The Danger Deepens: 2014 Neustar Annual DDoS Attacks and Impact Report This report compares DDoS findings from 2013 to 2012, based on a survey of 440 North American companies, including 139 businesses delivering technology...
- Establish Cyber Resiliency: Developing a Continuous Response Architecture Many enterprises fail to proactively prepare the battlefield for a data breach by only leveraging outdated techniques that focus on the perimeter or...
- An Incident Response Playbook: From Monitoring to Operations As cyber-attacks grow more sophisticated, many organizations are investing more into incident detection and response capabilities. In this webcast, learn how to develop... All Cybercrime and Hacking White Papers | Webcasts