S.C. governor's post-breach data encryption claims are off-base, analysts say
"The governor's comments reflect unawareness of data security practices and are not at all reassuring," Litan added.
Pointing to weak data security practices at banks as a defense for the state's ineptness isn't a good strategy, said Richard Stiennon, a principal at IT-Harvest.
"Critical data, especially personally identifiable information, must be protected and Social Security numbers linked to names, ranks at the top" of the list of items that need to be protected, he said. "Encryption technology is readily available for data stores. It is not cumbersome to encrypt data. To the contrary, it is easy to do and most retailers and payment processors do it regularly."
Some security vendors also took the governor to task for her claims about encryption technology being cumbersome to implement. "Anyone remotely familiar with security best practices knows that all sensitive data should be encrypted," said Torsten George, vice president of worldwide marketing and products for risk management vendor Agiliance.
Typically, the decision not to encrypt sensitive information is driven by budget limitations rather than by industry standards or best practices, George said.
Haley's comments are based on outdated assumptions, said Todd Thiemann, senior director of product marketing at data encryption vendor Vormetric. While encryption technologies used to be somewhat difficult to deploy, these days the technology is not all that complicated, he said.
"Most state data breach laws, including California, Massachusetts and Nevada, call out Social Security numbers as a category of information requiring protection," Thiemann said.
Under most state data breach laws -- including South Carolina's -- encryption provides businesses with safe harbor from notification in the event of a data breach, he noted.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan or subscribe to Jaikumar's RSS feed . His e-mail address is email@example.com.
Read more about Cybercrime and Hacking in Computerworld's Cybercrime and Hacking Topic Center.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Who's Spying on You? You're aware of the threats of malware to your business but what about the ever-changing ground rules? Cybercriminals today are launching attacks against...
- HP HAVEn: See the big picture in Big Data HP HAVEn is the industry's first comprehensive, scalable, open, and secure platform for Big Data. Enterprises are drowning in a sea of data...
- What Datapipe customers need to know about the new PCI DSS 3.0 compliance standard This handy quick reference outlines what PCI DSS 3.0 is, who needs to be compliant and how Alert Logic solutions address the new...
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well...
- The New Way to Work Knowledge Vault This Knowledge Vault focuses on how, in today's increasingly virtual world, it's more important than ever to engage deeply with employees, suppliers, partners,... All Cybercrime and Hacking White Papers | Webcasts