17.07.2015 Views

Download eBook (PDF) - Red Gate Software

Download eBook (PDF) - Red Gate Software

Download eBook (PDF) - Red Gate Software

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2 – Data Classification and RolesWith the sensitivity classes that were used in the HomeLending database wecould expect data handling polices that would provide some of the followingverbiage:All data that is categorized with a "High" sensitivity class shall not bedisplayed in plain text through an application. If presentation through anapplication is unavoidable the data must be truncated or obfuscated in somefashion to which the data does not present full disclosure.All data that is categorized with a "High" sensitivity class shall not betransmitted electronically through e-mail, sent to another party through filetransfer protocol (FTP), transferred through an interface to another system,published on the internet or other publishing media, sent within a facsimiledocument. If transfer of this information is required through electronic means,this data must be encrypted with a strong key that is no less than 128 bits inlength.All data that is categorized with a "High" sensitivity class must not be stored inplain text on any data storage device including databases, spreadsheets,documents, backup files and flat files. The storage of this data must either betruncated or encrypted with a strong key that is no less than 128 bits in length.The storage and retention period of this data must be in compliance withgovernment regulations, industry standards and corporate policies.All data that is categorized with a "Medium" or "High" sensitivity class mustnot be stored on a portable device, such as a thumb drive, CD, DVD or harddrive within a laptop, in plain text. If storage on a portable device is required,this data must either be truncated or encrypted with a strong key that is no lessthan 128 bits in length.All data that is categorized with a "Medium" or "High" sensitivity class shallnot be provided in plain text on printed reports or documents. If printing isrequired, this data must be truncated or obfuscated in such a fashion that theplain text no longer presents a security threat.SummaryWith our sensitivity classes defined, our database roles established, membersassigned to the roles, our data handling policies defined, and having evaluatedthe data within our database and documented it, we are now ready to take alook at how our database schema may need to be designed, or re-architected, toprotect our sensitive data.61

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!