Skip to main content

Protegrity Privacy by Design Report

Page 1

PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS


1

INTRODUCTION

3

A DEFENCE-IN-DEPTH STRATEGY

4

THE FOUNDATIONAL PRINCIPLES OF PRIVACY-BY-DESIGN (PBD)

5

TEN PRINCIPLES OF DEFENCE

6

1 END-TO-END DATAFLOW

7

TYPICAL ENTERPRISE ARCHITECTURE

8

2 DATA SECURITY LIFECYCLE

9

DATA SECURITY LIFECYCLE ENABLES SECURE DIGITAL DISRUPTION

10

3 DISCOVERY

11

4 TOKENISATION

12

5 LOG ANALYTICS

13

GENERAL ARCHITECTURE OF ESA AND DATA PROTECTOR

14

6 DATA SECURITY POLICY

16

7 LAST LINE OF DEFENCE

18

8 ROLE-BASED ACCESS CONTROLS

21

9 REFERENTIAL INTEGRITY

22

10 TOKENISATION SECURITY

25

SPECIFIC RECOMMENDATIONS TO PREVENT AND COUNTER CYBER ATTACKS

54

DEFENCE-IN-DEPTH – BLUEPRINT FOR ACTION

56

APPENDIX


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

INTRODUCTION The World Economic Forum Global Risks Report 2019 identifies Data Fraud and Theft, and Cyber-Attacks as the fourth and fifth greatest threats to the Global economy. For organisations on the receiving end of these events the impact can be profound. In the four days immediately following the announcement of their breach, Equifax suffered a $5.3bn loss in market capitalisation (representing one third of their total value), Yahoo was hit with a $350m write-down in their valuation by Verizon following their data breach and US retailer Target incurred total expenses in the region of $236 million. Closer to home, Singapore’s Personal Data Protection Commission (PDPC) imposed fines totalling S$1m following the cyber-attack on SingHealth in June 2018 and the costs of implementing the recommendations from the Committee of Inquiry (COI) could grow to many multiples of that. Collectively, figures from Juniper Research1 suggest that by 2022 data breaches will have cost organisations globally “a cumulative total of $8 trillion in fines, lost business and remediation costs” over a five year period. Whilst it can be easy to be blindsided by the scale of these figures and although governments and organisations need to divert a considerable amount of resources to limiting the impact from these events, these figures are outstripped by the market opportunity created by the rise of data sciences. The McKinsey Global Institutes paper on competing in a data-driven world2 estimates that “open data can help unlock $3 trillion to $5 trillion in economic value annually across seven sectors”. In the face of this opportunity, it is insufficient for organisations and governments to revert to the outdated zero-sum approaches to data privacy that prioritise data protection at the expense of creativity and innovation. Instead they need to devise a way to accommodate both very legitimate interests.

The recent healthcare data breaches in Singapore have alarmed many stakeholders and have created a heightened sense of awareness of the importance of data security across the government and public sector and for citizens and residents. Although it is important not to lose sight of the impact of data breaches on a personal level, it is also important to put the scale of the breach and consequence of implementing measures to safeguard against future breaches into context. According to Business Insider3, SingHealth was the 19th largest breach of 2018. Whilst significant in its own right, the largest breach (Aadhar) was nearly 1,000 times larger at 1.1 billion. Conversely, with Singapore’s drive to become Asia’s big data hub, the development of Smart Nation in Singapore and the widespread adoption of Artificial Intelligence (AI) and Internet of Things (IoT), data and analytics are an increasingly critical component of Singapore’s economy and must be given the tools and support to grow if it is to maintain its position on the global scale.

1 Juniper Research, Cybercrime & Data Breaches to Cost Business $8 Trillion over the next 5 years https://www.juniperresearch.com/press/press-releases/cybersecurity-data-breaches 2 McKinsey Global Institute, The Age of Analytics: Competing in a Data-Driven World https://www.mckinsey.com/~/media/McKinsey/Business%20Functions/McKinsey%20Analytics/Our%20Insights/The%20age%20of%20 analytics%20Competing%20in%20a%20data%20driven%20world/MGI-The-Age-of-Analytics-Full-report.ashx 3 https://www.businessinsider.sg/data-hacks-breaches-biggest-of-2018-2018-12/?r=US&IR=T

1


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

When considering best practices for Data Protection and privacy, former Information and Privacy Commissioner of Ontario, Canada Dr. Ann Cavoukian’s report “Privacy by Design, The 7 Foundational Principles, Information and Mapping of Fair Information Processing”4 is widely accepted as setting out best practices for achieving world class data privacy practices. The approach developed by Cavoukian was published in 2009 and ratified by International Assembly of Privacy Commissioners and Data Protection Authorities the following year, before being incorporated into the European General Data Protection Regulation (GDPR) in May 2018.

In comparison, the COI’s recommendations provide almost perfect alignment with six of the seven principles. The one principle that is largely overlooked in the recommendations, despite being of particular importance to Singapore, is Principle Four, which breaks with conventional wisdom on privacy and suggests that restricting access to data to preserve privacy is a zero-sum game. In order to achieve a positive-sum game that caters for both the needs to open datasets for analytics whilst protecting them from breaches, organisations need to embrace technologies and relentlessly pursue approaches that help them achieve and satisfy both interests simultaneously.

4 https://iab.org/wp-content/IAB-uploads/2011/03/fred_carter.pdf

2

Helping organisations to liberate data by protecting the data itself, whilst maintaining referential integrity of the datasets and the interoperability of data between systems is the cornerstone of Protegrity’s solution and as such, it forms the basis of the recommendations set out over the following pages. Protegrity has worked with over 200 Fortune 1000 organisations globally and been recognised by Gartner as a market leader in Data-Centric Audit and Protection.


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

A DEFENCE-IN-DEPTH STRATEGY As organisations worldwide become increasingly aware of how vulnerable they are to cyber-crime, whether it is DDOS, breach of security, ransomware or malicious hacking, the onus is on the organisation to reduce its exposure to risk. However, as cyber threats are constantly evolving, so is the defence against them; organisations are realising that strong defences must be revisited and reworked, keeping pace with the evolutionary arms race that cyber-crime has become. A DEFENCE-IN-DEPTH STRATEGY ALIGNS WITH THE FOUNDATIONAL PRINCIPLES OF PRIVACY-BY-DESIGN (PbD) More than two decades ago, when most of the technology industry just worried about Y2K or the internet collapsing, visionary Dr. Ann Cavoukian realised that those doomsday scenarios were not the ones about which people should worry. Working as the Information and Privacy Commissioner for Ontario and with a background in psychology, criminology and law, she realised that systemic effects of ever-growing information systems will affect people’s lives in more increasingly profound ways than ever imagined. In order to realise the true benefits of this technology growth, she recognised the need to incorporate the social and human value norms into the design of those technology systems. She developed the Privacy by Design framework – an approach that is characterised by proactive, positive-sum (full functionality) measures. The objectives of this framework are not just to ensure privacy and personal control over one’s information but also to gain a sustainable competitive advantage in doing so for organisations themselves.

“ Open data can help unlock $3 trillion to $5 trillion in economic value annually across seven sectors” 3


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

THE FOUNDATIONAL PRINCIPLES OF PRIVACY-BY-DESIGN (PBD) 1 Proactive not reactive; preventative not remedial Privacy-invasive events are anticipated and prevented before they happen. Focus is on before-the-fact prevention, not a remediation after a problem (e.g. data breach) occurs.

2 Privacy as the d efault setting This means maximum privacy protection offered as the baseline – the maximum degree of privacy is ensured by automatically protecting personal data in any given IT system or business practice. No action is required on the part of the individual to protect their privacy – it is built into the system, by default.

3 Privacy embedded in design By embedding privacy in the design and architecture of IT systems and business practices by treating it as any other system requirement (e.g. usability, performance), privacy becomes an essential component of the core functionality being delivered.

4 Full functionality – positive-sum, not zero-sum Implementation of privacy is not compromising business goals. All legitimate interests and objectives are accommodated in a positive-sum, win-win manner without unnecessary trade-off. It is an approach of ‘and’ vs ‘or’ having to, for example, accommodate privacy and security at same time.

5 End-to-end security – full lifecycle protection The security measurement is to be implemented through the whole information management lifecycle and embedded in the system prior to the collection of the information. All data is to be securely retained and then securely destroyed at the end of the process, in a timely fashion.

6 Visibility and transparency – keep it open All stakeholders must operate according to any stated promises and objectives and must be subject to independent verification. Systems, component parts and operations must remain visible and transparent to all users and providers alike.

7 Respect for user privacy – keep it user-centric Architects, engineers and operators are to protect the interests of the individual by offering such measures as strong privacy defaults, appropriate notice and empowering user-friendly privacy options. 4


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

TEN PRINCIPLES OF DEFENCE REDUCING FUTURE RISK In the last decade Privacy by Design has gained traction in policy circles around the world. Unanimously passed in 2010 as an International Standard by the International Assembly of Privacy Commissioners and Data Protection Authorities, it has been translated into 40 languages, been recognised by the US Federal Trade Commission in 2012 and included in EU GDPR legislation. These major achievements are testament to its strength. How these principles are used and built in to the engineering of products and services remains an open question; these as yet un-standardised features leave an open field for misinterpretation. An organisation can foster a defence-focused culture by adopting Privacy by Design, being data-centric, adopting an ‘assume breach’ mindset, maintaining rolling review and improvement programs, keeping abreast of security issues and, most importantly, being ready for attack.

ORGANISATIONS ADOPTING THE FOLLOWING TEN KEY PRINCIPLES FOR DEFENCE WILL BE ONE STEP AHEAD.

“But if that’s all you do, it’s not enough. I want you to go further. When I ask you to do Privacy by Design, it’s all about raising the bar. Doing technical measures such as embedding privacy into the design that you’re offering into the data architecture, embedding privacy as a default setting. That’s not a legalistic term. It’s a policy term. It’s computer science.”5

5 Quote: Dr. Ann Cavoukian transcript https://blog.varonis.com/interview-privacy-expert-dr-ann-cavoukian/

5


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

1 END-TO-END DATAFLOW • Protegrity’s data-first approach to protecting data itself ensures that information remains secure across the end-to-end dataflow. • Protegrity Prime simplifies enterprise data security with a total solution that ensures companies and their customers are always fully protected – enterprise-wide data, all the time, in all uses. It unifies data security, discovery, audit, management, and monitoring across all data silos in an organisation from a single dashboard. • Protegrity Prime delivers complete control and visibility of enterprise data, at rest or in transit, across all silos to ensure total data privacy and regulatory compliance, while enabling new datadriven innovation throughout the enterprise.

6


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

TYPICAL ENTERPRISE ARCHITECTURE

BI / ANALYTICS WEB SERVER

APP SERVER

DATABASE DATA WAREHOUSE

MAINFRAME

DATA SCIENCE / DECISION SUPPORT

ETL/ESB

SaaS

DATA LAKE

APPLICATIONS

API GATEWAY

BIG DATA

MPP

DATABASES

FILES

APPLICATIONS

MAINFRAME

GATEWAY

7


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

2 DATA SECURITY LIFECYCLE • Data Security needs to be an enterprise-wide, closed-loop operational system of Classification > Discovery > Protection > Monitoring > Enforcement. • Protegrity takes a data-first security approach to finding and protecting the data itself. This approach is iterative, rather than a one-off implementation, meaning the approach is continuously improving security. • Protegrity has used the Data-Centric methodology to protect Privacy by Design for the sensitive data of some of the largest companies in the world.

8


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

DATA SECURITY LIFECYCLE ENABLES SECURE DIGITAL DISRUPTION

CLASSIFICATION

DISCOVERY

Role-Based Access Controls

ENFORCEMENT

Protegrity Insight leverages machine learning algorithms to perform discovery

PROTECTION

Localised control – within country or business unit

Broad range of protection methods Protect at rest – in transit – in use – across all data sources

MONITORING

Centralised monitoring and integrations to all major SIEM tools 9


Protegrity Insight is a database agnostic sensitive Insight Features PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS information discovery and tracking tool, designed • Cross platform coverage • Highly scalable architecture, elastic to reduce, manage and control the risk associated and parallel processing, sampling with storing sensitive data as well as the disruption and partial results 3 DISCOVERY and financial impact of multiple or third party • Patent-pending classification technique with classifiers on enterprise data audits. multiple features Knowing where sensitive information exists sets realistic expectations for

Protegrity Insight for Discovery is a purposeThink of data regulation in terms of an iceberg – ignorance of what lies beneath built data discovery, classification and analysis the waterline is no excuse for noncompliance. Think about analytics in terms of a puzzle – without all the pieces it is impossible assess to see the bigger tool that helps organisations andpicture. understand Discover Successrisk exposure by showing where Starting data-driven projects with discovery and classification accelerates sensitive data resides. Organisations can then their completion, optimizes processes and consistency and quickly reduces analysecostand address critical compliance metrics enterprise and risk. Knowing where sensitive information resides realistic expectations for and protect data at rest, insets transit or in use managing the scope, cost and timeframe of data projects, including security across the entire enterprise and in the cloud. and regulatory compliance.

managing data projects. Discovery and classification of an organisation’s sensitive • Classifiers are weighted, based on information allows a fast and confident jumpstart for data-centric projects the probability of accuracy including GDPR, Payment Card Industry Data Security Standard (PCI DSS) and Health Insurance Portability and Accountability Act (HIPAA) compliance. Organisations can stay secure and in control of sensitive data exposure by continual measurement Insight Benefitsand assessment of gaps and violations. Organisations can identify and locate sensitive data across an entire enterprise, • Supports determining the scope of recognising what to protect without compromising business success. new projects Protegrity Insight for Discovery overcomes many of the challenges • Simplifies compliance with associated with traditional such dataas discovery tools: regulatory requirements GDPR Privacy Impact Assessments • Analysing large, distributed data stores is no longer slow and expensive and PCI audits, etc.

• Sensitivity confidence rating reduces risk • Insight into enterprise systems that

• Interpreting results is privacy no longer represent risk to data andmanual and high risk priorities are clearly identified security •• Agility to respond to an evolving data landscape is consistently assured Performance is independent of target system capacity

When Protegrity Insight for Discovery is integrated with the full suite of Protegrity data security solutions, an organisation’s security team can create and propagate the proper data protection policies and techniques across applications, data warehouses, mainframes, big data repositories and the cloud.

How Insight Works By continually measuring and assessing exposure, gaps, and policy violations, organisations be able • Goes through the data will sources it to drive timely actions and see an improvement in data protection confidence scores. is pointed at and opens as many items as possible to discover sensitive data wherever it exists Dashboard overview

Discover Simplicity Organisations that do not know where sensitive data resides find it hard 10 to prioritize data security and privacy risks, and regulatory goals, and thus

• Associates and records data classifications as directed (tags, labels, data element types…) • Positive results are stored and classifiers show a confidence


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

4 TOKENISATION Tokenisation is the process of replacing sensitive data with unique identification symbols that retain all the essential information without compromising its security. In its most basic form, it is simply substituting clear text for a random value (token) and keeping a lookup table (token vault) in a secure place, which maps the cleartext value to the corresponding token. The token data type and length typically remain the same as the cleartext and the token lookup table becomes the ‘key’, allowing the cleartext value to be retrieved from the token. Tokenisation protects sensitive data by substituting non-sensitive data. Tokenisation creates an unrecognisable tokenised form of the data that maintains the format of the source data. For example, a credit card number (1234-5678-1234-5678) when tokenised (2754-7529-6654-1987) looks similar to the original number and can be used in many operations that call for data in that format, significantly reducing the risk of linking it to the cardholder’s personal information. The tokenised data can also be stored in the same size and format as the original data, so storing the tokenised data requires no changes in database schema or process. Tokenisation allows an organisation to maintain control and compliance when moving to the cloud, big data and outsourced environments. Tokenisation does not have to use a mathematical process to transform the sensitive information into the token. There is no algorithm that can be used to derive the original data for a token.

1234 5678 1234 5678

2754 7529 6654 1987

Protegrity Vaultless Tokenisation (PVT) is a lightweight and powerful solution that eliminates the operational and management problems associated with vault-based tokenisation. PVT deploys a very small set of lookup tables of random values without having to store either sensitive data or tokens. As the tables do not grow with actual data, as they do with vault-based tokenisation, PVT is faster, more reliable, more secure, and can scale to a range of varied data protection tasks in addition to protecting credit card numbers, such as health and privacy information. PVT is perfect for distributed, high-volume workloads and multi-cloud architectures - the protection is done close to each cloud environment rather than having to communicate back and forth with a central vault, preventing breakaway silos and issues for data scientist joining together datasets.

11


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

5 LOG ANALYTICS rotegrity provides detailed logs of all attempts to access sensitive data; alerts and P thresholds can be configured to notify security personnel to investigate and respond to incidents where unauthorised or anomalous activity concerning the sensitive data has taken place. These logs can be used for effective incident response, but once Protegrity’s protection is applied to sensitive data, users not allowed by the Policy to see protected data in the clear will only be able to access the protected form of that data. Protegrity’s Enterprise Security Administrator (ESA) product can also be integrated into corporate monitoring tools where all activity in the client environment can be reported on from a central application or tool • During enforcement, the Data Protector sends a log of all operations and access attempts on the sensitive data back to ESA. Operations include protect and unprotect operations. Access includes authorised or unauthorised attempts to gain access, alter or delete sensitive data. • The health of the data protectors is monitored by ESA. The movement of policy and audit logs between ESA and Data Protectors is done through a secure channel. Even if this interface is not operating (e.g. ESA is down), once the policy is deployed, the security in the Data Protector will continue to operate according to the policy and audit logs will continue to be generated for later delivery to ESA.

12

AUDIT RECORD OF ALL ACCESS ATTEMPTS The audit function enables verification that the data security policy is being enforced, and if abuse of sensitive data is occurring. Audit logs capture authorised and unauthorised attempts to access sensitive data at all protection points. This level of granularity is critical to answering the question of, “Who touched what data, when and where?” – an important requirement for PCI DSS and HIPAA compliance. The level of protection is determined by the Security Officer, and in support of Separation of Duties (explained on page 20), only the Security Officer can control the level of audit logs to be captured. Auditing the enforcement of the data security policy is an integral part of the Protegrity Solution. Within the policy, the security team can specify what types of audit records (of activities on sensitive data) are generated, collected and returned to ESA for analysis and reporting. The Protegrity Data Security Platform can also collect audit logs on all changes made to policies by security administrators. Everyone, including the security team, must be made accountable.


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

Database Protectors

GENERAL ARCHITECTURE OF ESA AND DATA PROTECTOR

EDW Protectors

DSK

ESA Connect Agent DSK

Audit logs

Policy Enforcement Agent

DSK Enterprise Security Administrator

ESA

Policy for this data store

Big Data Protectors

Gateway Protectors

File Protectors Application Protectors IBM Mainframe Protectors

13


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

6 DATA SECURITY POLICY The foundation for protecting sensitive data in the enterprise is the data security policy each organisation creates within ESA, based on relevant regulations and its particular needs and circumstances. The purpose of the policy is to enable the Security Officer to determine, specify and enforce the following data security rules: • What type(s) of sensitive data needs to be protected? • Which method(s) will be used to protect the sensitive data? • Who will have access to the sensitive data? • Where in the enterprise will the policy be enforced? • Access and process audit attempts by who, to what data, where and when. These rules are specified centrally in ESA and there may be more than one policy implemented per organisation. The ESA allows security officers to easily specify data security requirements and distribute them across the enterprise to be executed locally. Once the policy is determined and set in ESA, it is requested by Protegrity Data Protectors for enforcement on installed systems, ensuring consistent enterprise-wide security. These protection attributes are stored in a security catalogue or database that is separate from the database where the secured data resides. The method used to protect data in a database with the use of the security catalogue is protected by the US Patent No. 6321201. 14

WHAT SENSITIVE DATA WILL BE PROTECTED? Before embarking on a data security project, the data that is to be protected needs to be classified. Classification is typically performed by the security or compliance team in response to requirements of a specific law or regulation, such as PCI DSS, GDPR or HIPAA. Such compliance is usually determined through an audit from a Qualified Security Assessor (QSA). In other cases, companies may wish to protect data, including Personally Identifiable Information (PII), in accordance with company compliance and governance mandates for sensitive data. In ESA, the definition of these sensitive data fields is performed by creating ‘Data Elements’ for each field or type of data that is classified as being sensitive.

HOW WILL THE SENSITIVE DATA BE PROTECTED? Different data protection scenarios sometimes require different forms of protection. For example, files in transit are typically encrypted, credit card protection is moving from encryption to tokenisation, and sensitive data being sent to third parties (for research or in context to monetisation efforts) is often masked. Protegrity offers a variety of protection methods to address the wide array of data types and use cases. In some cases, these data protection methods can also be used simultaneously to protect different types of data for different purposes:


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

• MONITORING: Minimal security for lower risk data. Sensitive data monitoring creates reportable audit logs of all access attempts on the data without necessarily altering it or restricting access and enables the security team to observe such activity. This is often used in conjunction with stronger methods, such as encryption or tokenisation. • STRONG ENCRYPTION: Standards-based AES 256 strong encryption, regarded by many including government agencies as the gold standard for data security, uses a keybased algorithm to turn any data into unreadable binary code. • PROTEGRITY VAULTLESS TOKENISATION (PVT): A highly scalable form of tokenisation – replaces real data with random fake data of the same data type and length – developed by Protegrity to overcome the performance issues associated with format-preserving encryption and traditional tokenisation methods. In addition to tokenisation’s relatively well-known effectiveness in protecting payment card data, PVT also delivers versatile de-identification, anonymisation and pseudonymisation for privacy data. • FORMAT PRESERVING ENCRYPTION (FPE): A form of encryption that preserves data types, useful for situations where an encryption standard, such as AES, is a requirement. The performance of FPE is slower than tokenisation, which means it is usually not used when tokenisation is a viable option. The Protegrity platform supports both Data Type Preservation (DTP) and NIST standards based FPE. • STATIC AND DYNAMIC DATA MASKING: Static Data Masking, derived from one-way format-preserving PVT, is a non-reversible form of data protection ideal for nonproduction environments, secondary use healthcare research scenarios and data monetisation. PVT also enables Dynamic Data Masking (on-the-fly), based on the data security policy.

First Name

Last Name

E-Mail Address

SSN / NID

Account Balance

Credit Limit

DOB

Medical Code

sjjya

fksyek

sjjya.fksyek@Protegrity.com

372-72-2064

$400,000

$801,840

09/17/91

756

ldeu

fleoah

ldeu.fleoah@Protegrity.com

214-03-9200

$381,116

$279,128

10/22/88

502

leosf

xpshr

leosf.xpshr@Security.com

519-61-2624

$257,637

$197,982

10/08/04

651

fhy

llgud

fhy.llgud@Protegrity.com

404-36-6295

$750,000

$14,453

09/13/77

521

cirse

pdeu

cirse.pdeu@Protegrity.com

341-45-9879

$482,699

$970,045

07/15/79

700

qood

vhetaf

qood.vhetaf@Security.com

485-17-4672

$151,012

$456,820

07/20/66

830

ggorg

ftrjso

ggorg.ftrjso@Protegrity.com

393-74-4548

$161,562

$408,627

06/03/02

537

gyal

kdety

gyal.kdety@Security.com

656-07-5956

$5,295

$100

12/08/98

700

Ideu

artuw

Ideu.artuw@Protegrity.com

048-50-5927

$1,500,200

$750,000

08/06/79

700

bblad

erks

bblad.erks@Security.com

313-54-4985

$250,000

$50,000

09/07/59

502

fhy

ssd

fhy.ssd@Protegrity.com

316-04-2530

$100,000

$10,000

04/05/50

756

De-Identified Data (in blue) using Tokenisation

Tokenisation allows for protection of individual identifiers while preserving the ability to analyse the data. This is a process known as de-identification. This is a risk-based approach that allows organisations to render sensitive data unreadable without obfuscating all the data. As opposed to an all-or-nothing approach, de-identification allows for use of the data without compromising identities of individuals. In the example in Figure 3, the data of every individual is protected and unreadable and it is still possible to perform business processes and analytics on the anonymous data to examine financials against medical procedures.

WHO SHALL HAVE ACCESS TO THE SENSITIVE DATA? Different individuals (e.g. Finance, HR, Legal) in an organisation sometimes need to be authorised by the security team to view different specific unprotected sensitive data (cleartext data). The authorisation criteria for each user are described in the data security policy and users are defined in the form of members and roles. Each role is associated with a level of authorisation granted to all of its members, including specific data access privileges, similar to that which organisations already perform using directory services. The Protegrity Data Security Platform delivers tight integration with directory services such as Lightweight Directory Access Protocol (LDAP) and Active Directory. The integration enables organisations to continue to manage workforces with directory services. 15


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

7 LAST LINE OF DEFENCE Perimeter-based security, once considered to be the keystone of enterprise protection, is unable to offer the support or protection organisations need against hackers. Even with the most sophisticated perimeter security technologies in place, attackers continue to uncover new ways to penetrate networks and access sensitive data. Monitoring the perimeter is ineffective – simply put, perimeter monitoring will not deter hackers. Advancements in big data security analytics may help to fill gaps over time, but companies cannot afford to be complacent. Cloud concerns are warranted – the rapid rise of cloud data storage and applications has led to unease among adopters over the security of data and an urgent need to have the right cloud protections in place. Physical and digital borders add complexity; companies that conduct business internationally – for example, via a third-party service provider or business process outsourcer (BPO) – face a separate set of data securityrelated challenges that perimeter-based approaches cannot protect. Criminals will find a way into organisations’ systems and there is only one way to secure enterprise data at all points from creation to destruction: data-centric protection through encryption or tokenisation. Statistics show this is already having a huge effect on the way organisations secure data; in 2017, less than 3% of data breaches involved encrypted data6. Organisations must accept that being hacked is inevitable and therefore it is imperative that any stolen data that is rendered useless through encryption. Criminals will not find a way to use stolen data meaningfully if organisations encrypt or tokenise it; PVT can also offer a means to maintain transparency and usability of the information – security must be balanced with usability.

6 https://breachlevelindex.com/assets/Breach-­Level-­Index-­Report-­2017-­Gemalto.pdf 7 Public report of the Committee of Inquiry into the cyber attack on Singapore Health Services

16

To educate business users about data security and enforce a consistent message across the enterprise, it is essential that organisations establish a strict data security policy. Such a policy needs to address several key factors, including: which information needs security, who can access it, where and when it can be accessed, how it is protected, and keeping thorough logs on all access attempts. It is also essential to ensure that any data access policy is driven at the enterpriselevel, versus a traditional system-by-system silo approach. If the latest headlines are any evidence, it is clear that perimeter-based security has failed to keep up with the demands of modern enterprises. Traditional organisation ‘walls’ have disappeared and the techniques and technologies used by attackers have far outpaced the capabilities of network-based approaches alone. Data-first security technology such as PVT has been developed to protect data at a highly granular level, without limiting the its value in analytics and other business processes.

“Key Finding #5: While our cyber defences will never be impregnable, and it may be difficult to prevent an Advanced Persistent Threat from breaching the perimeter of the network, the success of the attacker in obtaining and exfiltrating the data was not inevitable.” 7


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS OUTSIDE THREAT

PERIMETER SECURITY Message Security (anti-virus, anti-malware)

DLP

Perimeter Firewall

NETWORK SECURITY Secure DMZs

Honeypot

Message Security (anti-virus, anti-malware)

ENDPOINT SECURITY

Perimeter IDS/IPS

Perimeter Firewall

APPLICATION SECURITY

Content Security (anti-virus, anti-malware)

PO

LIC

YM

AN

AG

Dynamic App

Database Monitoring / Scanning

EM

EN

T

Host IDS/IPS

Review WAF

DATA SECURITY DAR/DM/DU Protection Data/Drive Encryption Data Classification DLP Data Integrity Monitoring Identity & Access Data Wiping Cleansing Management PKI

Security Awareness Training Security Policies & Compliance Threat Modelling Vulnerability Assessment

DLP

Testing Static App Testing / Code

PREVENTION Cyber Threat Intelligence IT Security Governance Penetration Testing Risk Management Security Architecture & Design

Honeypot

Endpoint Security Enforcement

Desktop Firewall

Perimeter IDS/IPS

OP

E

TIO RA

NS

MONITORING & RESPONSE SENSITIVE DATA ASSETS

Continuous Monitoring and Assessment Security Dashboard Situational Awareness Security SLA/SLO Reporting Digital Forensics SIEM Escalation Management SOC/NOC Monitoring 24/7 Incident Reporting, Detections Response (CIRT)

17


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

8 ROLE-BASED ACCESS CONTROLS Protegrity provides an authorisation layer to sensitive data based on the roles defined in the security policy. Supporting Separation of Duties is one of the principles driving Protegrity’s security policy. Every attempt to access sensitive data will be recognised and intercepted by Protegrity protectors. Data will be returned in its protected or unprotected form, depending on the rules specified for the role associated with the user.

Users can be authorised to see data in the clear, protected, partially protected (e.g. three last digits of a phone number), masked, or suppressed with a null value; it is also possible to return an exception in case of an unauthorised attempt. Roles can be synchronised with an existing identity management authentication mechanism (Active Directory, LDAP, Databases, and File-based) and have two factor authentication, so only users or groups specifically authorised by the policy will be able to see data in the clear – even for administrators and service accounts with high privileges.

AUTHORISED

UNAUTHORISED DATABASE ADMINISTRATOR

DATA SCIENTIST

Name: Joe Smith DoB: 19-04-1987

ANY STORAGE MECHANISM: File, Database, Hadoop

18

RESPONSE

Logs

POLICY ENFORCEMENT AGENT

AUTHORISED

Name: esu wusoj DoB: 11-03-1900

DATA PROTECTED AT REST

ANY STORAGE MECHANISM: File, Database, Hadoop

REQUEST

POLICY ENFORCEMENT AGENT

REQUEST

Logs

DOES THE REQUESTER HAVE THE AUTHORITY TO ACCESS THE PROTECTED DATA?

Name: esu wusoj DoB: 11-03-1900

Select Name and DoB from customers

RESPONSE

Select Name and DoB from customers

DOES THE REQUESTER HAVE THE AUTHORITY TO ACCESS THE PROTECTED DATA?

NOT AUTHORISED

Name: esu wusoj DoB: 11-03-1900

DATA PROTECTED AT REST


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

PROTEGRITY SUPPORTS ROLE-BASED ACCESS CONTROL (RBAC) THROUGH THE FOLLOWING FEATURES: • CENTRALLY MANAGED ENTERPRISE-LEVEL CROSS-PLATFORM INDEPENDENT RBAC Protegrity customers define, grant and revoke enterprise-wide access to data from a single interface in a pure cross-platform way. There is no need to know particularities and properties of underlying systems. • CENTRALISED CROSS-PLATFORM POLICY DESIGN AND MANAGEMENT Part of the RBAC definition is a policy design. Protegrity customers will be able to define data access policies in a cross-platform way from a central location. • CROSS-PLATFORM POLICY ENFORCEMENT ON ALL PLATFORMS Agents enforce data protection policies in a cross-platform way according to capabilities of underlying operating systems and technologies. • COMPREHENSIVE SEPARATION OF DUTIES With Protegrity, neither root, nor systems administrators, nor DBA, nor DBC level administrators can view protected data in the clear. There is nothing that can be modified on the system to grant an access. All endpoints are accessible by everyone, only authorised users get meaningful results. Walking out of the data centre with a Protegrity-protected dataset and privileged credentials will not result in exposure of protected data. • INTEGRATION WITH ALL MAJOR USER DIRECTORIES INCLUDING ACTIVE DIRECTORY AND LDAP Protegrity’s Data Discovery Tool Insight allows organisations to monitor and track the data stored and evaluate all data for sensitivity and report where potential sensitive data is not protected. • LEAST PRIVILEGE The Protegrity solution abides with the principle of least access; users see the least amount of information they need in order to perform their administrative and operational duties, reducing risk should privileged credentials become compromised by phishing or malware attacks. Protegrity ensures that personal information is secure by default; only authorised users have access to the data in the clear. Data access and protection type is defined by a central privacy policy, which varies per role, system and the context of use. 19


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

SEPARATION OF DUTIES (SoD) The term ‘Separation of Duties’ refers to the separation or segregation of the security officers, who have control over the data security policy (including granting access to sensitive data), from systems administrators who work with or manage environments containing sensitive data, and who may, or may not require access to the data. Security officers control access to sensitive data through the data security policy set in ESA, preventing unauthorised access to sensitive data in the clear by roles such as DBAs, programmers, system engineers and outside parties. Security officers can also be prevented from viewing the data in clear as part of SoD. Protecting data at rest or in transit with Protegrity involves replacement of the data in the clear with protected data. This will ensure any direct access to the data by deliberate bypassing of the Protegrity protection will only result in protected values being obtained. Configuration of High Availability Protection, support for Disaster Recovery requirements and features for backups of policy and keys from ESA allows clients to always be able to access data in the clear. The Protegrity platform abides with the Principle of Least Privilege. Protegrity ensures that personal information is secure by default. Only authorised users have access to the data in the clear. Data access and protection type is defined by a central privacy policy, which varies per role, system and the context of use. Role

Name

DOB

City

Phone Number

Default (protected)

0YFPi VXSthG

1553-01-16

xKsuO

0044692376501

Database Admin

0YFPi VXSthG

1553-01-16

xKsuO

0044692376501

Analyst

0YFPi VXSthG

1994-04-05

London

0044692376501

Customer Service

John Smith

1553-01-16

London

0044######570

20


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

9 REFERENTIAL INTEGRITY With Protegrity’s technology, referential integrity of a dataset is preserved within tables, data warehouses, files and any other systems, on-premise and in the cloud. The same protected value will always yield the same ciphertext token, ensuring that the data is uniformly protected across all supported platforms. By preserving its referential integrity, Protegrity preserves the analytical value of the data: information from various systems can be combined by the analytical teams and applications just as it was prior to implementing Protegrity’s protection.

UNPROTECTED (IN THE CLEAR)

Credit card numbers are regulated by PCI DSS and as such must always be protected. In the examples illustrated below they are stored in two completely separate and different platforms. With Protegrity the data element is defined in ESA as “DE_CCN” and used on both Mainframe and Hadoop to protect the credit card number. As the same data element is used on both platforms, the ciphertext (or token) returned is unique to an individual credit card whilst simultaneously being the same on both platforms, making the data both referential and able to be securely analysed.

WITH NATIVE PROTECTION

PROTECTED WITH REFERENTIAL INTEGRITY

Credit Card

Credit Card

Credit Card

Credit Card

Credit Card

Credit Card

5416 9284 6848 5106

5416 9284 6848 5106

S7FS76G7809F9GFG57IF5G87S

135GL1343HG6JIG4D7K476D8I6

7091 0142 6179 7102

7091 0142 6179 7102

4916 5743 3160 2729

4916 5743 3160 2729

S7FS76G7809F9GFG57IF5G87S

DF2DIR6FG76JJ980H8GJFDHZ6

4258 3957 8596 0697

4258 3957 8596 0697

5211 4814 9926 8213

5211 4814 9926 8213

FG98HGS7HGF4GFHSF3FH7GN

8FGADF75H4H97H0SDF5H024M

0758 1697 3258 8555

0758 1697 3258 8555

4485 8486 5609 7936

4485 8486 5609 7936

98DGDA87DT5H4GGH35FG67GI

2LK35H0SD97G3KIL3H5S0DS79

4417 0187 9967 5237

4417 0187 9967 5237

ESA 21


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

10 TOKENISATION SECURITY More and more organisations are moving from encryption to tokenisation, recognising that it is a more secure, more flexible and more cost-effective approach – they realise that tokenisation goes beyond simply reducing the burden of PCI compliance and is the best way to protect all private or sensitive data, unlock business value and minimise risk in every scenario including GDPR and HIPAA.

22

The advantages of tokenisation security to organisations include: • Scalable security across heterogeneous environment. Tokenisation is able to preserve data types to truly establish privacy and security by design, no matter what differing storage types exist across an organisation • The ability to partially reveal data helps maintain privacy and security of data by design without hindering revenue-generating services and business processes. • Role-Based Access Controls (RBAC). Fine-grained control of role-based access on the data level, leveraging existing and established roles within an organisation enforced by the wide catalogue of Protegrity protectors Tokenisation security sees heavy use in credit card processing, where it is an effective means to transport sensitive codes securely. Tokenisation is primarily used for the secure transportation of Primary Account Numbers, or PANs, the large identifying numbers found on all payment cards. These are tokenised into a seemingly random collection of numbers and letters, which can then be de-tokenised by authorised parties when necessary. In this way, customer PANs can be exchanged in secure financial transactions, safe in the knowledge that they are incredibly difficult to intercept.


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

PROTEGRITY VAULTLESS TOKENISATION (PVT)

BENEFITS OF PROTEGRITY VAULTLESS TOKENISATION

• HIGH PERFORMANCE AND UNLIMITED SCALABILITY Fast creation of new data tokens and quick recovery of the original data when needed. The solution scales linearly to increase the throughput required for demanding business requirements. • FLEXIBLE DEPLOYMENT Deploy in a distributed environment, including on each node in a Massively Parallel Processing (MPP) system, or in a central topology. Neither require any replication between the token servers. Multiple deployment options allow organisations to optimise performance and security for each unique use case. • MULTIPLE TYPES AND FORMATS PVT delivers flexible, format-preserving token types, including numeric, alphanumeric, date, time, address and other structured tokens. Tokens can also be generalised or created with ‘bleed through’, or part of the original data exposed. This business intelligence can be useful when applications use only part of the sensitive data for processing.

Performance Fastest tokenisation on the market, near zero latency

Scalability Easy to create redundancy, no replication required

Security No vault means no tokens to steal and no vulnerable PANs

Compliance Supports PCI, HIPAA, GDPR and other requisite protection standards

Ease of use Deploy and grow with commodity hardware

Unity Centrally control policy, key management, and reporting across the enterprise

• PLATFORM APPROACH Protegrity customers are able to leverage platform-agnostic vaultless tokenisation capabilities throughout the heterogeneous enterprise. Protegrity supports a wide range of operating systems, databases, EDWs, mainframes, big data platforms and cloud environments.

FEATURES • No vault means no unwieldy, ever-expanding database, or the DBA time to support it • No replication means no costly real-time replication service, or the engineer time to run it • Lightweight tokenisation engine easily runs on cost-effective commodity hardware • Ease of scalability and management keeps ongoing maintenance costs in check

23


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

SPECIFIC RECOMMENDATIONS TO PREVENT AND COUNTER CYBER ATTACKS

25


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

The 16 recommendations outlined are applicable to any organisation responsible for holding large databases of personal data and include the safeguarding of data as well as its defence; organisations must be mindful of data security requirements and be continually looking for ways to improve them. With a data-first approach to adoption, organisations can be confident about effective and robust cyber defence: RECOMMENDATI ON

1

An enhanced security structure and readiness must be adopted by IHiS and Public Health Institutions

Cybersecurity must be viewed as a risk management issue and not merely a technical issue; decisions should be carefully deliberated at the appropriate management level, to balance the trade-offs between security, operational requirements and cost. Organisations should make use of the support staff, advisory services and CISO experience available to them, but the focus must be on protecting the data itself, a process that is part of an iterative mindset, rather than a one-off implementation. A one-off project can protect an individual system or dataflow at a particular moment in time, but systems and dataflows are continually evolving, meaning vulnerabilities are introduced or the relevance and integrity of some of the controls are undermined over time. Embedding “Privacy by Design” as an architectural principle requires organisations to develop an operational capability for defining, governing and enforcing the Data Security Policy. A data-centric methodology will protect even the most sensitive data. 682

All organisations, whether commercial, non-profit or governmental, need to build a secure organisation to ensure long-term success. This means that organisations must implement and maintain a strong security posture, including in relation to cybersecurity. This is particularly relevant to organisations like IHiS and the public health institutions (“PHIs”), which own and/or maintain public sector IT systems which contain large databases of personal data – failing to secure the organisation can lead to potentially devastating consequences beyond the four walls of the organisation.

RESPONSE Data-first security provides the ‘last line of defence’ for organisations when considering their overall security posture. Traditionally, organisations address data security requirements by implementing siloed technologies to protect the data at rest (e.g. within databases, data warehouses, the cloud, etc.). Whilst these solutions help to protect data within a specific context, data needs to be unprotected as it moves between systems and silos, creating a point of vulnerability that could be targeted by hackers. The heterogeneous nature of these solutions also makes it extremely difficult to ensure that an organisation’s data security policy is implemented consistently across all environments. Auditing of these systems to ensure conformance can also become a major undertaking. By implementing an enterprise-wide data security solution, organisations can be confident that the policy is deployed consistently, auditing is maintained through a single ‘pane of glass’ and data can move across full end-to-end dataflows in a protected format, without losing the utility of the data across the disparate systems. PROTEGRITY

26

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

684

A comprehensive IT security policy, on its own, serves little purpose. For such a policy to be effective in fact (as opposed to in theory), the practice on the ground must comply with policy. Hence, any gaps between policy and practice must be addressed.

RESPONSE With an enterprise-wide data security solution, organisations can quickly audit the protection deployed to the various data sources across the on-premise and cloud infrastructure and ensure that the data security policy has been effectively implemented for all sensitive data elements. By combining the protection with discovery and logging capabilities, organisations can easily identify data sources that represent the greatest vulnerability and gain insights into how sensitive data is used throughout the data flow. PROTEGRITY

687(b)

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

Audit and compliance. Regular audits and compliance checks are also important. They help to identify non-compliance, and if findings are properly remediated, help to bridge any gaps between policy and practice. To this end, it is important that the ongoing discussions between IHiS and the GIA on the three lines of defence are properly reviewed and that an appropriate decision is taken soon. IHiS acknowledges that the three lines of defence model is a good target model. The key benefit of implementing an effective three lines of defence model is that it improves coverage of risks and controls by identifying and refining the population of risks and controls, and it appropriately allocates the ownership and performance of these risks and controls across the lines of defence. As a result, any unintended risks and gaps in controls can be avoided, and unnecessary duplication of work should be avoided by removing layers of redundant controls. An effective model of three lines of defence will, therefore, better address the gaps between policy and practice.

RESPONSE Manual audits are extremely costly and prone to human error. When auditing security posture across disparate data silos, the skills needed by auditors to reliably perform a meaningful assessment of the on-premise and cloud infrastructures creates considerable cost and complexity for auditors. By leveraging a centrally managed enterprise-wide data security solution, organisations can automate many of the tasks needed to perform audits and quickly and effectively identify data sources that are not adequately compliant. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

27


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

688-689

To properly implement defence-in-depth, active steps must be taken to identify and secure vulnerabilities that are “out there”, particularly in legacy systems, to protect against future exploitation. Defence-in-depth also involves people, technology and operations49: (a) People. Trained security personnel should be responsible for securing the network and systems; (b) Technology. A variety of technological measures should be used for layers of protection; and (c) Operations. Preventative activities (e.g. penetration testing, software patching, access controls, etc.) and reactive activities (monitoring, detection, blocking isolation, etc.) required to maintain security should be put in place. Several measures for this purpose will be set out below.

RESPONSE Achieving defence-in-depth from a data security perspective requires protection of data from as close as possible to where it is captured and created and for the data to remain protected through until it is consumed. This requires the ability to discover, protect, monitor and enforce the policy across the full end-to-end data flow. Without the ability to achieve this end-to-end, organisations risk introducing vulnerabilities in the interfaces between and within systems that fall outside of the scope of the enterprise platform. Enterprise-wide data security systems require the ability to discover and protect sensitive data across a wide range of platforms from big data and cloud environments, through to mainframes, Relational Database Management System (RDBMS), data warehouses and everything in between. PROTEGRITY

692

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

As regards the principle that more valuable assets should be protected behind more layers of defence, it is imperative that stronger, multi-layered security mechanisms should have been in place around SingHealth network’s crown jewels – the electronic medical records of all SingHealth patients. This includes safeguards in the system to trigger alarms when abnormal activities are attempted or executed on the crown jewels.

RESPONSE The notion that, “more valuable assets should be protected behind more layers of defence” is very closely aligned with the principles of data-centric security and Privacy by Design. Whilst electronic medical records are the crown jewels in the case of SingHealth, it is important to understand the specific data elements within the medical records that are the most valuable and subsequently require the greatest level of protection. Achieving that requires an upfront effort to classify all identifiers and quasi-identifiers, discover where those data elements reside within the respective systems, apply the appropriate protection method (e.g. tokenisation, encryption, masking, anonymisation), role-based access controls and monitoring of how the sensitive data elements are consumed by the user community. These capabilities are core functionality for an enterprise-wide data security solution and need to be applied consistently across full end-to-end dataflows in order to ensure adequate safeguards are in place. PROTEGRITY

28

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

693

An issue was raised in the Inquiry on whether it is realistic to expect a legacy system such as the SCM to have such in-built safeguards. The experts’ view on this issue is clear: for legacy systems, there should be a regular process to constantly review such systems and penetration testing should be built-in as part of safety review. CE, CSA is also of the same view.

RESPONSE Where systems lack adequate safeguards to protect the data, the most effective and efficient method to protect the data is by protecting the data itself. Legacy systems are often difficult to support and have limited availability of the skills needed to routinely make changes, consequently using protection methods (such as tokenisation and format-preserving encryption) that retain the data type and length of the data elements, the data can be protected without changes needing to be made to the systems directly. Whilst this may not prevent an intruder from gaining access to the data, the data they obtain would be meaningless to them and of no value financially or politically to the perpetrator. Performance impact can be minimised using vaultless tokenisation as it allows for protection and unprotection operations to be performed in a distributed manner across the environment and mitigates the security risks of maintaining a token vault. PROTEGRITY

694

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

Hence, all legacy systems in the public healthcare sector must be reviewed as a matter of priority. This must involve a thorough review and assessment of legacy systems/applications, including penetration testing and consideration of whether such systems/applications should be isolated or decommissioned (if hardening them is not possible). In this regard, IHiS can consider commissioning an independent external expert to conduct an initial review of all the legacy systems in the public healthcare sector. This will ensure that the review will be objective and provides assurance that the systems have been thoroughly reviewed. Thereafter, subsequent regular reviews can be conducted internally.

RESPONSE Sensitive data discovery is an important component of any assessment of legacy systems and applications. By ascertaining the level of sensitivity of the data, organisations can make an objective decision about which systems to prioritise to have the most impact on their ability to protect sensitive information. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

29


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

710

Another example is that of ensuring appropriate management visibility when it comes to security incidents. Management visibility is important – only by being wellinformed will management be able to react in time and appropriately. It is unrealistic to expect a leader to know everything and to know it all the time. However, processes and tools should be available to allow management to have as much visibility as possible over security incidents.

RESPONSE Organisations that implement enterprise-wide data security solutions have peace of mind that even when a system is breached, the data retrieved is of little value to the perpetrator: to get access to the valuable data, they need to gain access to a user account that is authorised to view the data in the clear and perform the function needed to unprotect the data. These additional steps add complexity for the perpetrators. Furthermore, all operations performed to unprotect the data are logged by the system, providing the management team with an audit trail of how the sensitive data has been used and whether the data itself has been accessed. By performing sensitive data discovery on compromised datasets, organisations can quickly determine whether changes have been made to the dataset in order to exfiltrate the data. PROTEGRITY

30

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

RECOMMENDATI ON

2

Cyber stacks must be reviewed to assess if they are adequate to defend and respond to advanced threats

Organisations should employ centralised, heterogenous solutions enterprise-wide, and include legacy technology to identify gaps in the cyber stack by mapping against existing security technologies. Once discovered, gaps must be filled by acquiring endpoint and network forensics capabilities, however, a proactive protection of data itself mitigates risk from gaps. An ongoing and iterative approach to data-centric audit and protection (DCAP) will mitigate gaps through continuous monitoring and enforcement. The effectiveness of current endpoint security measures must be reviewed to fill any gaps that an attacker could exploit. DCAP, with centralised and automated access monitoring and logging at the Database Activity Monitoring (DAM), Endpoint Detection and Response (EDR) and Advanced Threat Protection (ATP) layers, can overcome the limitations of a silo approach by protecting data itself. Network security must be enhanced to disrupt the ‘Command and Control’ and ‘Actions on Objective’ phases of the Cyber Kill Chain and application security for email must be heightened. If an attacker gains a foothold, their reward is data that is of no value to them. As above, protecting data itself fortifies these silo approaches and helps to mitigate human error as cyber attack methods evolve. Organisations should adopt enterprise solutions architected with protection policies that can be configured once in a central repository. These policies will provide consistent data protection at rest, in transit and in process across an organisation’s entire environment. 720

An enterprise-wide data security solution provides the last line of defence for organisations, deepening the overall integrity of the security stack. By embracing these technologies, the data security policy can be defined and maintained within the solution, rather than simply a document, providing practitioners responsible for the security of the data with an intuitive mechanism for validating that the data security policy has been deployed consistently and accurately across the estate.

RESPONSE An Enterprise-Wide Data Security platform provides the last line of defence for organisations, deepening the overall integrity of the security stack. Through embracing these technologies, the Data Security Policy can be defined and maintained within the platform, rather than simply a document, providing practitioners responsible for the security of the data with an intuitive mechanism for validating that the data security policy has been deployed consistently and accurately across the estate. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

31


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

721

In Gen. Alexander’s expert opinion, a comprehensive cybersecurity capability should be deployed and implemented, as cybersecurity teams cannot protect against threats that they cannot see and that are not detected by the cyber tools they are using. His vision of such a capability is one that not only includes the current set of cyber tools, but also leverages an expert system, behavioural analytics (which is rigorously tested and proven in the networks) and a collective security capability. In his opinion, such a capability would have been important in detecting the theft of credentials, lateral movement in the network, and data exfiltration in the Cyber Attack. Dr Lim echoes the sentiment that organisations like SingHealth need to subscribe to more effective cyber tools to analyse and detect more advanced and sophisticated cyber attacks.

RESPONSE Data-centric security ensures that information exfiltrated from an organisation’s infrastructure in a protected format is of little value to an unauthorised perpetrator. Only once the data has been unprotected (detokenised or decrypted) can anything meaningful be inferred from it, if the data security policy has been adequately defined and applied. Gaining access to the functions needed to unprotect the data typically requires this to be performed on large datasets, or over long periods of time, from within the organisation’s network and doing so creates a large digital footprint. With the appropriate logging in place to detect uncharacteristic operations on sensitive data, organisations increase the chances of detecting a breach while it is occurring, rather than having to rely on post-mortem examination of the events. PROTEGRITY

730

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

We recommend the implementation of a centralised enterprise-level forensics platform for collection and analysis of digital evidence. Features of such a system would include: (a) 360-degree visibility across all endpoints; (b) Remote collection of forensic artefacts; and (c) An ability to search and collect forensic evidence across multiple devices concurrently.

RESPONSE Industry leading data security platforms support standard integrations to Security Information and Event Management (SIEM) and other logging tools. Whilst visibility across the endpoints is useful, it is the data itself that organisations needs to protect. Consequently, logging needs to include access to sensitive data elements. By leveraging these interfaces, a much more comprehensive view can be gathered of the actions being taken to exfiltrate sensitive data. PROTEGRITY

32

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

733

Almost all modern network equipment such as routers, switches, firewalls etc. support the ability to capture data regarding network traffic that flows in and out of such devices. While it appears that IHiS had tools to capture network traffic information, they did not have the means to analyse it effectively for forensic purposes.

RESPONSE Identify sensitive data in amongst all other data moving around an organisations network can be an incredibly complex task. By logging access to sensitive data itself, organisations can significantly reduce the effort needed to ascertain the level of threat posed from an intruder. PROTEGRITY

772

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

Monitoring of east-west traffic. After an attacker has gained access to a network, seeing, detecting and tracking their actions is crucial to reducing the likelihood of their mission objective (e.g. exfiltration of data) being achieved. East-west visibility of network traffic refers to the ability to see malicious activity that is contained within the network.

RESPONSE Deploying data security consistently across the enterprise and logging attempts to unprotect data across end-to-end dataflows, from front-end systems to extract, transform, load (ETL) and Enterprise Service Business (ESB) tools, application programming interface (API) gateways, mainframes, data warehouses, databases, big data environments and cloud systems, organisations can gain a comprehensive view of how likely it is that an attacker has achieved their mission objective of exfiltrating data in the clear. Tokenised or encrypted values are of little value to the attacker. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

33


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

RECOMMENDATI ON

3

S taff awareness on cybersecurity must be improved, to enhance capacity to prevent, detect, and respond to security incidents

Front-end users are often the weakest link in cybersecurity; organisations must ensure that access to data is granted appropriately on a need-by-need basis. Access to key important data must be restricted to only those who need access and permissions reviewed regularly. Cyber-hygiene among users must continue to be improved; many attempts to steal data are phishing and malware attacks that target the privileged users in an organisation, such as administrators and DBA accounts. Protecting the data with appropriate products will ensure its protection, even from those with privilege user access, but still allow these users to perform normal administrative and operational duties. Organisations should implement a Security Awareness Programme in order to reduce organisational risk; staff must be aware that cybersecurity is everyone’s responsibility, but organisations can use additional provision to alleviate the security burden and mitigate risk of human error. IT staff must be equipped with sufficient knowledge to recognise the signs of a security incident in a real-world context. Organisations can use automated monitoring and alerts and training to ensure any anomalous behaviour is detected and identified at the earliest possible opportunity. External support can provide the ability to monitor protection and unprotection activities, set thresholds for normal activities concerning these activities and provide alerts when abnormal activity is observed. 809

All staff must be trained to recognise suspicious activity that may point to a cyber breach. Suspicious activity can include a number of different observables such as abnormal access patterns, database activities, file changes, and other out-of-the-ordinary events that can indicate an attack. Being able to recognise these activities is important. Employees should be trained to recognise common examples of suspicious activity: (a) Unusual database activity – Abnormal database activity can be caused by either internal or external attacks. (b) Account abuse – The abuse of privileged accounts is a common sign of an attack. (c) Changes in account privileges – Unexplained changes in account privileges are a sign that an attacker is trying to gain access to the network using a user’s credentials. (d) File changes – Changes in file configuration, including files being replaced, modified, added, and deleted, without explanation. (e) Suspicious network behaviour – Another sign of an attempted infiltration from external sources is unusual network behaviour.

RESPONSE When building up a profile of how users in particular roles typically interact with sensitive data, it is possible to build up a baseline of behaviours that can be considered usual. As an attacker will be looking to exfiltrate large volumes of data (either in a batch or over long period of time), the characteristics of accounts compromised typically fall outside of the range of usual behaviour for a role. By logging all protect and unprotect operations performed directly on the sensitive data itself, it can be easy to identify behaviour that may signal a potential breach. Following this up with discovery of sensitive datastores, changes to the structure or security posture of the datastore can be easily detected and actions can be taken to revoke access and remediate the vulnerabilities detected. PROTEGRITY

34

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

RECOMMENDATI ON

4

Enhanced security checks must be performed, especially on critical information infrastructure (CII)

Organisations must regularly conduct vulnerability assessment and detailed knowledge of where sensitive data is will assist in the prioritising of CII security checks. Reducing the amount of private data by deidentifying it will reduce the scope of work within the enterprise and mitigate the impact of oversights. Organisations must, where feasible, carry out safety reviews, evaluations and certification of vendor products. Penetration testing must be conducted regularly, and best practice is to share the results with the organisation’s security provider. Organisations should also carry out red teaming periodically and consider threat hunting as part of their security approach. Protecting data itself mitigates the impact of enhanced security check inadequacy - if all else fails privacy will still be preserved.

RECOMMENDATI ON

5

Privileged administrator accounts must be subject to tighter control and greater monitoring

Organisations must create and maintain an inventory of administrative accounts in order to facilitate rationalisation of such accounts where only users or groups of users specifically configured by policy will see data in the clear. This process should be a be supported by centrally-controlled and enforced policies so external security support can configure default access to be set to accounts that do not have the ability to see any data in the clear. All administrators must use two-factor authentication when performing data administration tasks. Authentication must be built into systems and systems configured to require privileged accounts related to the installation, configuration and operation security products to have two-factor authentication. Use of passphrases instead of passwords should be considered to reduce the risk of accounts being compromised and password policies must be implemented and enforced across both domain and local accounts. External security services should be configured to connect with corporate LDAP and Active Directory user identification directories to manage access to data. Server local administrator accounts must be centrally managed across the IT network. This layered approach, supported by an automated, centralised security policy, means access to data will be on a needs-only basis, with standard questions being asked to ascertain need - Who? What? Where? When? Why? How? Service accounts with high privileges must be managed and controlled and there should be strict authentication and monitoring, as well as logging, reporting and alerting. There must be user identification and password management features that control the administrative user identification required to install and maintain security products. Protecting data itself mitigates the impact of compromised privileged accounts – if all else fails privacy will still be preserved.

35


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

RECOMMENDATI ON

6

Incident response processes must be improved for more effective response to cyber attacks

To ensure that response plans are effective, organisations must test them with regular frequency. All attempts to protect or unprotect sensitive data must be logged and thresholds configured to alert security personnel that unauthorised or unusual activity concerning sensitive data has occurred. Pre-defined modes of communication must be used during incident response. Alerts should be configured to send emails to the key stakeholders or emailing lists required to investigate and respond to incidents concerning unauthorised access of sensitive data. Early detection of anomalous or unusual access to data means a quicker response. The correct balance must be struck between containment, remediation and eradication, and the need to monitor an attacker and preserve critical evidence. The information and data necessary to investigate an incident must be made readily available, so organisations should ensure they centrally log details of what data has been accessed and when, but sensitive data must never be shown in the clear for users unless specifically allowed to see it unprotected. 942

The traditional prevention-dominant approach to cybersecurity, which focuses on defending the perimeter, has failed to prevent intrusions. The reality is that no network is impenetrable. Prevention is crucial – organisations cannot lose sight of it as the primary goal. However, a new proactive approach to security is needed to enhance capabilities to detect threats that will inevitably slip through the perimeter defences.

RESPONSE Protecting sensitive data itself across an organisation’s infrastructure provides the best methods for proactive security. Attackers not only need to gain access to the network, but also need to then understand how the sensitive data elements have been protected, the mechanism to unprotect them and to gain access to an authorised user account in order gain access to the sensitive data. These steps all need to be performed whilst still in the company’s network. Without following these steps, any data that is exfiltrated as a result of breaching the perimeter is of little to no value to the attacker. PROTEGRITY

36

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

947

Technology. The ASOC must be equipped with the right tools to do its job. This includes a suite of technology that provide the right level of visibility over the organisation’s operations, commensurate with its security posture. The suite of technologies may need to be updated periodically, as cyber attack vectors evolve. Some examples include: (a) Security information and event management (“SIEM”) solutions; (b) Intrusion Detection System (“IDS”)/Intrusion Prevention System (“IPS”) solutions; (c) Threat and vulnerability management tools; (d) Filtering technologies; (e) Data loss prevention tools; (f) Traffic/packet inspection solutions; (g) Data analytics platforms; (h) Reporting technologies; and (i) Forensic tools.

RESPONSE Data Loss Prevention (DLP) technologies are extremely useful within a pre-defined organisational boundary, but they often fall short when data extends out to cloud systems and spans multiple networks. Furthermore, the operational overhead that can result from poorly configured DLP rules can hinder the business and result in passive configurations being deployed that limit the utility of these technologies. By protecting the data itself, at rest, in transit and in use, alongside DLP technologies, the consequence of a breach can be significantly reduced, without hindering business. The logging capabilities provided by enterprise-wide data security solutions also help to build out a more complete SIEM view and help to pinpoint the specific sensitive data elements that may have been breached. By combining with the analytic capabilities of these solutions, more comprehensive insights into the use of sensitive data can be gained with minimal effort. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

37


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

RECOMMENDATI ON

7

Partnerships between industry and government to achieve a higher level of collective security

Organisations should ensure that threat intelligence should be shared. Security functions have the capability to integrate logging information into third party tools, meaning logging data can be assembled with other centrally-monitored information to provide a complete view of activity concerning sensitive data. Partnerships with Internet Service Providers (ISPs) should be strengthened. Organisations should look beyond their own borders for defence, using and strengthening cross-border and cross-sector partnerships. Where possible, organisations should use enterprise-wide protection capabilities that can span global operations. Sharing of sensitive data with partners or third parties should be configured to allow them to see some, none or all data in the clear, as is required to work with partner organisations. Organisations should use a network to defend a network, applying behavioural analytics for collective defence. In addition, organisations should continue to review and enhance logging and monitoring capabilities to ensure that analytics are ever more robust.

RECOMMENDATI ON

8

It security risk assessments and audit processes must be treated seriously and carried out regularly

Organisations must carry out IT security risk assessments and audits in order to ascertain gaps in their policies, processes and procedures. Security tools that have logging and reporting capabilities can assist in providing a clear picture of the use and protection of sensitive data and provide detailed information on attempts to access sensitive data to ensure data protection policies are being applied. IT security risk assessments must be conducted on CII and mission-critical systems annually and upon specified events. Security tools with logging and reporting capabilities can assist in providing a clear picture of the use and protection of sensitive data and provide detailed information on attempts to access it to assist in ensuring data protection policies are being applied. Organisations must ensure that audit action items are remediated. Discovery of sensitive data helps prioritise where risk assessment should focus and organisations should determine where sensitive data lies within their environment on a continuous and automated basis to ensure newly-created sensitive data is also protected. Protecting data itself mitigates the impact of risk assessment and audit inadequacy – if all else fails privacy will still be preserved.

38


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

RECOMMENDATI ON

9

Enhanced safeguards must be put in place to protect electronic records

Given the high degree of digitalisation and interconnectivity and the risks at the national level to organisations’ sensitive data, adopting Recommendation 9 is critical for ensuring the enduring successful adoption of all other recommendations. Organisations must formulate a clear policy on measures to secure the confidentiality, integrity, and accountability of electronic records. There should be automated policy enforcement using products with architecture designed to ensure all policy definition is performed centrally so consistent application of protection is performed and referential integrity of the data across platforms and technologies used remains consistent and unbroken. Organisations should identify sensitive data, then assign role-based access controls ensuring privileged access is centrally and automatically controlled, thus reducing risk from internal threats. Databases containing sensitive information must be monitored and reported on in real-time for suspicious activity to be identified and acted upon. Organisations should ensure end user access to data is made more secure; authentication should be role-based and on a need-to-know access basis. Attacks can be blocked through policy-based rules that control access to data, but organisations should also take measures to secure data-at-rest in a way that ensures its business value for analytics and data sharing is maintained. Measures can include granular tokenisation and encryption; vaultless tokenisation de-identifies PII with fewer performanceoverhead related issues than encryption. Controls must be put in place to better protect against the risk of data exfiltration. Data loss can be prevented by applying protection as close the source of the data as possible and detecting and blocking unauthorised access to it by context, throughout the dataflow, using role-based access controls and minimising privileges to reduce internal threats. 1023

EMRs undoubtedly present many benefits. They improve patient care, and coordination of care, through enhanced access to patients’ medical information by all members of the healthcare team. The platform chosen for SingHealth to store EMRs was the SCM. The SCM operates like a dashboard, holding information such as patient records, diagnostic data, and medical history. This is very sensitive information. As the Cyber Attack has demonstrated, it is critical to protect the security and confidentiality of such medical records.

RESPONSE Whilst it is important to protect EMRs and ensure that perimeter security surrounding the database is adequate, given the nature of private health information, not all data elements within the EMRs are equal - without being able to identify the specific patient, knowing that patient X had a test performed is of very little value to an attacker. By finding sensitive identifiers and quasi-identifiers within the EMR’s and applying tokenisation or format-preserving encryption to those values, an additional layer of protection can be achieved that is difficult for an attacker to bypass, without hindering the ability of healthcare professionals to deliver care to patients. The same can be applied to any system of record used to support critical business functions and the user communities that rely on these systems. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

39


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

1024

The volumes of data exfiltrated by attackers in some of the largest breaches reported in recent years has been colossal. Exfiltrating this data without detection is no small feat but adding additional protection by securing data itself, the effort required increases exponentially. By protecting all sensitive identifiers and quasiidentifiers within a dataset, an attacker would need to unprotect the data prior to exfiltration, increasing the chances of them being detected. Furthermore, logging capabilities mean that every operation performed to unprotect sensitive data is recorded and reported on.

RESPONSE The volumes of data exfiltrated by attackers in some of the largest breeches reported in recent years has been colossal. Exfiltrating this data without being detected is no small feat. However, by adding the additional layer of protection provided by security the data itself, the effort requires increases exponentially. By protecting all sensitive identifiers and quasi-identifiers within a dataset, the attacker would need to unprotect the data prior to exfiltration. Increasing the chances of them being detected. Furthermore, the logging capabilities provided mean that every operation performed to unprotect sensitive data elements is recorded and reported on. PROTEGRITY

1026

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Protecting the perimeter proved insufficient against the attacker in this case, and in any event, the threat to EMRs may come from malicious insiders. It is recommended that, network security aside, data-centric security measures must be implemented to:

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

(a) Ensure the confidentiality and integrity of medical records; (b) Protect against any reasonably anticipated threats or hazards to the security or integrity of such information; and (c) Protect against any reasonably anticipated use or disclosure of such information.

RESPONSE Organisations should adopt a foundation for protecting sensitive data in the enterprise based on data-centric security policies that cover relevant regulations and circumstances. Policies enable the Security Officer to determine, specify and enforce data security rules. Protecting data at rest or in transit substitutes data in the clear with protected data to ensure direct access to data by deliberate bypassing of the protection will only result in protected values being obtained. HIPAA mandates data privacy and security provisions for safeguarding medical information, compliance with which requires organisations to have defined policies and procedures in place not just for data protection. Security officers should prevent unauthorised access to sensitive data in the clear by roles such as DBAs, programmers, system engineers and outside parties. As such, policies should include the principle of Separation of Duties (SoD) to ensure the segregation of the security officers who have control over the data security policy (including granting access to sensitive data), from systems administrators who work with or manage environments containing sensitive data, and who may or may not require access to the data. Security officers can also be prevented from viewing the data in the clear as part of SoD objective. Confidentiality means only those allowed to view sensitive data in the clear will be allowed to see the unprotected form of that Data Integrity means that data or information will not be altered or destroyed in an unauthorised manner. PROTEGRITY

40

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

A clear policy on measures to secure the confidentiality, integrity and accountability of electronic medical records must be formulated 1027

The HITSPS is silent on the issue of measures (generally) to protect the confidentiality, integrity and accountability of EMR. The HITSPS relates only to a narrow subset of “sensitive information” and even then, provides very little detail on control measures for “sensitive information”

RESPONSE All data elements that represent identifiers or quasi-identifiers for an individual need to be protected. While some regulations may be limited in the definitions they provide for what constitutes sensitive data, industry best practices exist that clearly define the sensitive data elements that need to be protected. Leveraging sensitive data discovery tools, organisations can quickly gain visibility of where sensitive data resides and take actions to protect it and monitor how the it is being used. PROTEGRITY

1028

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

Given the importance and sensitivity of the PII contained in EMR, it is important to have a comprehensive policy document that applies to the protection of EMR. This policy must document and make clear the measures that are in place to protect the EMR. We elaborate on some key measures that should be addressed in the policy, in the following sections

RESPONSE Organisations should adopt a foundation for protecting sensitive data in the enterprise based on data-centric security policies that cover relevant regulations and circumstances. The purpose of the policy is to enable the Security Officer to determine, specify and enforce the following data security rules: • What type(s) of sensitive data shall be protected? • Which method(s) will be used to protect the sensitive data? • Who shall have access to the sensitive data? • Where in the enterprise shall the policy be enforced? • Audit of access and process attempts by who, to what data, where and when. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

41


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

1029

The policy should provide for limits on access and provide screening controls so that only authorised staff can access patient data. Role-based access control helps to restrict EMRs to users who are made members of a certain role according to their responsibilities (e.g. doctor, nurse, clinician etc) or corporate position. Role-based access is already in place, but the classes of persons to whom access is granted, the extent of the access granted, should be reviewed as part of the wider post-Cyber Attack review. The Committee notes SingHealth’s perspective that the “implementation of IT projects is meant to serve, support and improve patient care, and that an appropriate balance will have to be struck when assessing the feasibility of IT projects”.

RESPONSE Role-based access controls are an integral part of any enterprise-wide data security solution and provide an added layer of granularity to existing controls. While application-level role-based access controls determine who has access to specific modules, forms or workflows within an application, complementing these with data-centric role-based access controls provides the flexibility to explicitly grant or restrict access to specific data elements. By doing so organisations can explicitly limit access to sensitive data to only the users who have a legitimate business need to view them in the clear. Furthermore, masking rules can be applied when unprotecting data to further limit the sensitive values that can be seen. PROTEGRITY

1030

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

The policy must establish clear access controls including: (a) Role-based security that restricts access to information based on pre-established categories of patients, duties and documents based on specific job requirements of the user; and (b) Tagging of sensitive data with status indicators that enable restriction of identified patients and encounters to only those with permissions to access such data.

RESPONSE Enterprise-wide role-based access controls should be based on policies that define, grant and revoke access to data from a central single interface in a cross-platform way according to capabilities of underlying operating systems and technologies. Neither root, nor systems administrators, nor DBA, nor DBC level admins should be able to view protected data in the clear or modify systems to grant access, including Active Directory and LDAP. Data discovery tools should allow organisations to monitor, track and evaluate all data for sensitivity and report where potential sensitive data is not protected. PROTEGRITY

42

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

1031

In short, the policy should follow the principle of least access – that is, staff should have access only to the resources they need to perform their daily tasks, and no more. Access to confidential data should be on a strict, need-to-know basis. Further, there should be no general access to patient data – staff should only be able to access the data when they need it for a specific purpose, and the scope of the data accessed should be tightly controlled to include only data essential to the completion of the task.

RESPONSE Abiding with the principles of least privilege ensures that personal information is secure by default so only authorised users have access to the data in the clear. Data access and protection type should be defined by a central privacy policy, which varies by role and system, and the context of use. PROTEGRITY

1032

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

Security measures should not only be geared towards external attackers – there is a real risk of patient data being compromised by insiders too. We recommend that the need for administrators, developers and support team to access patient data be reviewed. IHiS should aim for the least number of people possible to have access to the database. To the maximum extent possible, administrators, developers and support team should not be able to view actual patient data. Currently, IHiS staff such as database administrators are able to access medical records. The only control is that any access by such personnel is logged for audit purposes. This is insufficient, because it does not stop access, and by definition, the logs would only be useful to show that access had already taken place.

RESPONSE Abiding with the principles of least privilege ensures that personal information is secure by default so only authorised users have access to the data in the clear. Data access and protection type should be defined by a central privacy policy, which varies by role and system, and the context of use. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

43


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

1033

Administrators should have only the bare minimum privileges they need to do their job, and only during periods while they need access. The policy should adopt best practices for database security: (a) Unused accounts must be deleted. (b) Shared accounts should be prohibited – While administrators may find sharing passwords convenient, doing so makes proper database security and accountability almost impossible (c) Grant privileges to administrators, developers and support team only to the extent needed (read only vs insert/delete records, for example). (d) Access by administrators, developers and support team must be controlled/restricted to only the tables to which they need access. (e) A system for managing privileged accounts should be in place to provide authorised users with a temporary password with the privileges they require each time they need to access a database.

RESPONSE The main reason for restricting access for administrators, developers and support teams to only those which they need to access, is to limit the amount of sensitive data that they can access. By protecting the data at rest through tokenisation or encryption, the impact of users gaining access to superfluous data is reduced. The benefit to organisations of leveraging these capabilities it that it allows for data to be shared more freely with developer communities and helps to drive innovation agility without compromising security or compliance. Furthermore, referential integrity across systems is preserved with vaultless tokenisation, allowing users to analyse data and build models, without ever accessing sensitive information itself. PROTEGRITY

44

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

1034

The EMR system must document and keep up-to-date logs and maintain an audit trail of authorised access to the system by users. This means it must record how medical records are accessed, by whom, what information was accessed, and when. That way, security personnel can quickly investigate if they suspect an insider was involved in a data breach. As shown in the Cyber Attack, an external actor can also obtain credentials and masquerade as an authorised insider. Logging of access to the EMR from the front-end client can also therefore be essential to investigating unauthorised access by external attackers.

RESPONSE A data-centric approach to protecting sensitive information should be automated to capture and alert about anomalies within the following: • All protection, unprotection and reprotection operations • Operations of authorised and unauthorised access to protected data • All administrator activity including login, modifications to configuration and changes to policy Furthermore, it should be possible using the event log configuration to stop, pause or initialise the sending of the audit. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

Databases containing patient data must be monitored in real-time for suspicious activity 1040

Bulk queries during the Cyber Attack were not detected by any monitoring systems and came to light only by chance, when it was noticed by an alert employee (Sze Chun). Monitoring for such queries, which are indicative of unauthorised data harvesting, must be implemented at database-level.

RESPONSE There are plenty of legitimate business reasons why bulk queries may be performed, consequently monitoring bulk queries in isolation can generate a lot of false-positives and create a significant overhead for organisations. With data tokenised or encrypted at rest, bulk queries themselves are of less significance. Attackers looking to exfiltrate the data need to perform operations on the data whilst still within the network, in order to unprotect the data. These operations create a significant footprint and increase the chances of detection. Through logging all protect and unprotect operations and analysing the logs for anomalies in behaviour, unauthorised requests to unprotect large amounts of data can be easily detected and remediated. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

45


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

End-user access to the electronic health records should be made more secure Measures should be considered to secure data-at-rest 1053

In the Cyber Attack, the attacker was able to view the full details of the medical records stored in the SCM database, once he had gained access. This was so as there were no measures in place to secure the data-at-rest in the database.

RESPONSE When data is protected at rest, all unauthorised viewing and copying will be of data in a meaningless form. PROTEGRITY

1054

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

Data-at-rest refers to information stored in databases in filesharing servers, in backup tapes etc, and generally includes any data that is not being transmitted through a network (which is known as data-in-motion).

RESPONSE A data-centric approach to protecting data ensures end-to-end protection of data within an organisation, in use, in transit, and at rest. PROTEGRITY

1055

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

The amount of data that is being generated daily continues to increase exponentially. Given the rapid pace of development of cyber attacks, data-centric security measures must be deployed. These measures include safeguarding the data itself as it resides in repositories such as databases.

RESPONSE Organisations should seek data-centric products that scale both vertically and horizontally in order to process additional volumes of data as required. PROTEGRITY

46

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

1056

In general, mechanisms to protect data involve coding data in such a way that access to the data is restricted. This process can generally be referred to as “masking”96 and can occur at the central record repository. Techniques used to mask information in a patient’s medical record include data encryption and tokenisation a) Encrypting data-at-rest prevents unauthorised access by anyone who defeats normal system access controls. It alters the content of the data and stores it in encrypted form. This makes health data unreadable unless an individual has the necessary key or code to decrypt it. This would ensure that unauthorised individuals are not able to see the data in its original form. Dr Lim has recommended encrypting all data-at-rest, where possible, to protect against both internal and external malicious actors. Dr James Yip (“Dr Yip”), MOH’s Chief Data Advisor, also testified that it would be possible to encrypt patient databases and provide tiered access to the decrypted data. (b) Tokenisation also prevents unauthorised access to selected columns98 of data. Tokenisation can be used as an alternative to encryption on a column-by-column basis. Even if a database is compromised, tokenising PII (personally identifiable information, such as name and NRIC number) would effectively frustrate an attacker’s ability to query for the medical records of specific individuals. Dr Lim testified that even if the data cannot be wholly encrypted, key information can at least be anonymised and hashed. Even bulk downloads of medical records would provide the attacker with no means of ascertaining who the individual records relate to. As the full medical record is not encrypted, there would be less performance-overhead related issues, as compared with encryption.

RESPONSE Organisations should seek data-centric solutions that provide a variety of protection methods for securing information, including tokenisation, masking, strong encryption, datatype preservation and monitoring for anomalous behaviours. Masked or tokenised data embedded with business intelligence allows for secure storage of de-identified personal information and seamless analysis without risk to privacy. Tokenisation may be used in lieu of traditional masking which does not protect data at rest, only at the presentation layer, to ensure the most secure protection of sensitive data. Tokenisation can also maintain the same format as the values to be protected for less intrusive data security that minimises the need for application and environment changes. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

47


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

1057

It is acknowledged that encryption and tokenisation of data may have some impact on the operations of the PHIs, in terms of speed of access to patient records. However, such adverse impact should not be presumed without further study. As before, security should not be sacrificed merely for convenience, given the highthreat environment that exists today. Implementation needs to be carefully handled to minimise disruption to operations. An independent study should be conduct on the feasibility of implementing these measures in the EMR systems of the PHIs.

RESPONSE Next generation tokenisation protection operations are performed within memory in fractions of a second, and are proven to avoid negative impact to systems in terms of speed of access to protected data. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

Controls must be put in place to better protect against the risk of data exfiltration 1058

In many cases, victims of cyber attacks are not aware that the sensitive data is leaving their systems because their data outflows are not monitored. The movement of data across network boundaries must be carefully scrutinised to minimise its exposure to attackers.

RESPONSE By protecting sensitive data at rest, attackers are faced with the added challenge of having to identify that the data has been protected, determine the protection method(s) used, reverse engineer the protection process and attempt to achieve all of that whilst remaining undetected within the network. The time this adds to efforts to exfiltrate data can provide organisations with an opportunity for a proactive response to breaches. PROTEGRITY

48

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

Access to sensitive data must be restricted at both the front-end and at the database-level 1067

Database-level controls. During the Cyber Attack, there were no database-level controls that would have restricted the querying of sensitive data using SQL commands. This was a significant omission in the security of the SCM database, and was exploited by the attacker, who ran multiple queries to retrieve medical records of PM Lee.

RESPONSE The use of proven data-centric protection limits the success of SQL queries being performed on sensitive information because it cannot be accessed without going through the additional steps necessary for its unprotection. PROTEGRITY

1069

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

Similarly, even if encryption and tokenisation cannot be applied to all databases wholesale for performance reasons, steps should nonetheless be taken to encrypt or tokenise sensitive data. This is because such data constitutes an obvious high-value target for attackers. All the measures we have proposed including encryption and tokenisation apply with particular urgency to such sensitive data.

RESPONSE De-identifying high value private information as early in its lifecycle as possible using vaultless tokenisation ensures that an individual’s privacy is maintained without compromise to business systems or processes. Data-centric security ensures that protected data flowing throughout the enterprise can only be unprotected where and when approved by management and the data security team, further minimising risk of unauthorised access to sensitive data. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

49


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

RECOMMENDATI ON

10

Domain controllers must be better secured against attack

Organisations must ensure that operating systems for domain controllers are more regularly updated to harden these servers against the risk of cyber attack. Continual upgrade compatibility should be investigated and adopted where appropriate. Policy enforcement can ensure the attack surface for domain controllers is reduced by limiting login and administrative access and requiring two-factor authentication. Protecting data itself mitigates the impact of operating system update inadequacy – if all else fails privacy will still be preserved.

RECOMMENDATI ON

11

A robust patch management process must be implemented to address security vulnerabilities

Organisations must adopt a clear policy on patch management; priority should be given to the deployment of new patches and organisations by identifying the greatest risk and mitigating patch failure impact by protecting data itself. Security services can provide support and assistance with patching and should be taken advantage of to ensure protection provided is the latest and most secure. Protecting data itself mitigates the impact of patch management inadequacy – if all else fails privacy will still be preserved.

RECOMMENDATI ON

12

A software upgrade policy with focus on security must be implemented to increase cyber resilience

Organisations must formulate and implement a detailed policy on software upgrades. An appropriate governance structure must be put in place to ensure that the software upgrade policy is adhered to. Organisations should prioritise the deployment of software updates by identifying where data is at greatest risk using discovery tools to identify and locate sensitive data throughout the enterprise. Security industry and vendor expertise should be leveraged to assist organisations in keeping software updated and protected. Software failure impact, however, can be mitigated by protecting the data itself, making it worthless in the event of a breach. Protecting data itself mitigates the impact of software upgrade inadequacy – if all else fails privacy will still be preserved.

50


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

RECOMMENDATI ON

13

An internet access strategy that minimises exposure to external threats should be implemented

In light of recent cyber attacks, organisations must remain vigilant and review their internet access strategy. In formulating its strategy, an organisation should consider the benefits and drawbacks of unrestricted internet access and put in place mitigating controls to address the residual risks – ease of use must be balanced with risk. Security tools can intercept and protect data flowing over the internet or internal network, ensuring sensitive data is protected using de-identification as soon as possible within the enterprise environment and protecting data in transit to reduce risk. 1131

The appropriate internet access strategy is an issue of risk management. It requires consideration of resources, demands, infrastructure constraints, and operational imperatives. It is thus a decision that should be undertaken by the healthcare sector, weighing the full range of considerations. MOH has not come to an official position on the appropriate internet access strategy and has formed a horizontal committee to look into this issue, and weigh the balance between cybersecurity risks, patient safety, and cost.

1145

The real issue is how optimal these workarounds are. Dr Yip testified that the workarounds have come at the price of increased time and costs, loss in productivity and new risks, and in the long-term, may have adverse impacts, including manpower constraints and lower staff morale. We recognise these challenges and note that the healthcare sector will have to balance this challenge against the cybersecurity risks.

RESPONSE As noted by Dr Yip, limiting internet access is too restrictive for most organisations in all industries. As open sharing of data across the enterprise is an essential prerequisite for driving innovation, prohibitive controls could inadvertently cause more damage than the threat against which they are intended to protect. Focusing attention specifically on the sensitive data elements that need to be protected, and having policies that control access to data by role, ensures secure democratisation of data. PROTEGRITY

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

51


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

RECOMMENDATI ON

14

Incident response plans must more clearly state when and how a security incident is to be reported

Organisations must ensure a cybersecurity incident response plan for staff is formulated and deployed. The incident response plan must clearly state that an attempt to compromise a system is a reportable security incident and include wide-ranging examples of security incidents and the corresponding indicators of attack. Organisations can simplify incident response by reducing its impact with a data-centric approach to security; this will identify anomalies earlier, and reduce risk because sensitive data itself is protected. Logging and alerts will help flag when incidents occur and send out notifications to the required parties to start investigating. 1173

There are many different ways to tell if a system has been or is being compromised, but unless employees are able to detect, alert, and respond to these indicators in real-time, the ability to stop a cyber-attack in its tracks will be very limited.

RESPONSE Key to stopping a cyber-attack in its tracks is to slow the attack and exfiltration of sensitive data down for as long as possible by increasing the digital footprint needed for them to get to the data. By protecting sensitive data itself, logging all protect and unprotect operations and analysing the log data for anomalies in behaviour, organisations increase the chances of being able to stop data from leaving the network in an unprotected format. Exfiltrating tokenised data is of no value to an attacker and most would move on to other systems or organisations where they can more easily monetise their efforts. By extending protection to the dataflow end-to-end, the ability of the attacker to get at sensitive data through another system is reduced massively. Referential integrity across tokenised datasets ensures that its utility is maximised. PROTEGRITY

1180

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security

Staff should closely monitor any spikes in database activity, as that could be an indicator that the database has been compromised.

RESPONSE By protecting sensitive data itself, logging all protect and unprotect operations and analysing the log data for anomalies in behaviour, organisations increase the chances of being able to stop data from leaving the network in an unprotected format. Exfiltrating tokenised data is of no value to an attacker and most would move on to other systems or organisations where they can more easily monetise their efforts. By extending protection to the dataflow end-to-end, the ability of the attacker to get at sensitive data through another system is reduced massively. Referential integrity across tokenised datasets ensures that its utility is maximised. PROTEGRITY

52

End-to-End Dataflow

Data Security Lifecycle

Discovery

Tokenisation

Log Analytics

Data Security Policy

Last Line of Defence

Role-Based Access Controls

Referential Integrity

Tokenisation Security


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

RECOMMENDATI ON

15

Competence of computer security incident response personnel must be significantly improved

Organisations must appoint a competent and qualified Security Incident Response Manager who understands and can execute the required roles and responsibilities and ensure teams are well-trained and equipped with the necessary hardware and software to effectively respond to security incidents. Organisations can mitigate the impact of any inadequacy here with data-centric audit and protection, centrally reducing risk enterprise-wide by de-identifying data and simplifying responses with automated monitoring and reporting of all access attempts. Protecting data itself mitigates the impact of security incident response inadequacy – if all else fails privacy will still be preserved.

RECOMMENDATI ON

16

post-breach independent forensic review of the network, all endpoints and the SCM system should A be considered

Organisations should consider working with experts to ensure that no traces of the attacker are left behind. Again here a data-centric audit and protection approach reduces risk because personal data is de-identified and access to it is controlled by context. Protecting data itself mitigates the impact of post incident forensic inadequacy – if all else fails privacy will still be preserved.

53


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

DEFENCE-IN-DEPTH – BLUEPRINT FOR ACTION ORGANISATIONS MUST ENSURE A COHESIVE DATA-FIRST APPROACH IS WOVEN THROUGH ALL ELEMENTS OF PROTECTION AND DEFENCE:

• Discover risk – identify what sensitive data exists where, recognise and resolve security gaps early. • Protect data itself – if all else fails, privacy will still be preserved. • Be secure by design and in depth – assume breach and continually strive to reduce risk. • Keep one step ahead – always do more than the minimum. Organisations should identify trusted expertise and specialist solutions proven to ensure that cyber-risk is resolved early and access to personal data is limited by context, monitored and reported on.

54


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

IT IS IMPERATIVE THAT ORGANISATIONS APPLY DR. ANN CAVOUKIAN’S FOUNDATIONAL PRINCIPLES OF PRIVACY BY DESIGN TO DATA PROTECTION:

DEFENCE BY DESIGN 1 Proactive not reactive 2 Privacy as the default setting 3 Privacy embedded into design 4 Full functionality 5 End-to-end security 6 Visibility and transparency 7 Respect for user privacy

The COI recommendations reviewed in this paper are in almost perfect alignment with six of these principles. Protegrity, however, feels that the one principle that is largely overlooked in the recommendations, despite being of crucial importance, is the fourth, which breaks with conventional wisdom on privacy and suggests that restricting access to data to preserve privacy is a zero-sum game. Protecting data is of utmost importance, but it must be done in a way that does not impede business or limit profitability. In order to achieve a positive-sum game that caters for both the needs to open datasets for analytics whilst protecting them from breaches, organisations need to embrace technologies and relentlessly pursue approaches that help them satisfy both interests simultaneously.

This is the gap that Protegrity bridges – furthering data protection and enhancing security to the long-term benefit of organisations, rather than limiting procedures to the detriment of profit. 55


PRIVACY BY DESIGN: BALANCING DEFENCE-IN-DEPTH WITH ADVANCED ANALYTICS

APPENDIX TERMINOLOGY OF DATA PROTECTION The terms that are currently used in the context of privacy are often confusing as they may mean something totally different in the world of software engineering. DATA INVENTORY A data inventory is a fully described record of the data assets maintained by an organisation. The inventory records basic information about a data asset including its name, contents, update frequency, owner/ maintainer, data origin, and other relevant details. The details about a dataset are known as metadata. Frequently used synonyms are data catalogue/data dictionary. Note that data inventory is about all data, not just personal data.

DATA FLOW DIAGRAM (DFD) A data flow diagram illustrates how data is processed by a system in terms of inputs and outputs. As its name indicates its focus is on the flow of information, where data comes from, where it goes and how it gets stored.

DATA MAPPING Data mapping is a special type of data inventory that shows how data from one information system maps to data from another information system. It usually contains the following elements: • List of attributes for the original source of data • A corresponding (or ‘mapped’) list of attributes for the target data • Translation rules defining any data manipulation that needs to happen as information moves between the two sources, such as setting default values, combining fields, or mapping values.

56

DATA DISCOVERY FOR PRIVACY

ENCRYPTION

ANONYMISATION

Data discovery is a term used in data analytics to define the process and tools used to uncover hidden patterns and trends. In the context of privacy, this term is used for the technologies that automatically discover workflows across organisational collaborators that include personal data or identifying personal data existing in semi structured and unstructured environments.

Encryption is the process of encoding the information in such a way that only authorised parties can access it. The encryption translates data into another form, or code, so that only people with access to a decryption key or password can read it. Encrypted data is commonly referred to as ciphertext, while unencrypted data is called plaintext. A mathematical procedure for performing encryption on data is called an encryption algorithm. Rather than focusing on usability, the goal of encryption is to ensure the data cannot be consumed by anyone other than the intended recipient(s). Blowfish, AES RC4, RC5, and RC6 are examples of encryption algorithms.

Anonymisation is the process of turning data into a form which does not identify individuals. Anonymised data is defined as “data rendered anonymous in such a way that the data subject is not or no longer identifiable”. It means that data must be stripped of any identifiable information, making it impossible to derive insights on a discrete individual, even by the party that is responsible for the anonymisation.

DATA CLASSIFICATION Data classification, in the context of information security, is the classification of data based on its level of sensitivity and the impact to the organisation should that data be disclosed, altered or destroyed without authorisation. The classification of data helps determine what baseline security controls are appropriate for safeguarding that data. In general, it differs from information classification by its granularity – while information classification may be on a higher level (data type or even business process), data classification is usually on data elements. Data classification involves tagging and labelling data elements, which makes it easily searchable and trackable. Also, data classification may be performed for a number of reasons other than security, including ease of access, to comply with regulatory requirements, and to meet various other business or personal objectives.

HASHING Hashing is based on the concept of integrity, i.e. making it clear that something has been changed. Technically, hashing takes arbitrary input and produces a fixed-length string. In hashing, a new message is created from the original message in a particular way by which it cannot be reversed. Unlike encryption, it does not require a key to unlock the message. It is used for verifying files, etc. In this way, it ensures that the integrity is maintained. Once the message is hashed, its hash is used for comparisons. If the hash is the same for any message, then it is regarded as the same as the original message. These are different types of hashing algorithms used like MD5, SHA, RIPMEND, TIGER etc.

DATA MINIMISATION

TOKENISATION

This term was coined back in 1980 as part of OE CD principles. According to EDPS (European Data Protection Supervisor) the principle of ‘data minimisation’ means that a data controller should limit the collection of personal information to what is directly relevant and necessary to accomplish a specific purpose. They should also retain the data only for as long as is necessary to fulfil that purpose. In other words, data controllers should collect only the personal data they really need and should keep it only for as long as they need it.

Tokenisation is the process of replacing sensitive data with unique identification symbols that retain all the essential information without compromising its security. In its most basic form, it is simply substituting a randomly generated value (token) for a cleartext value and keeping a lookup table (token vault) in a secure place, which maps the cleartext value to the corresponding token. The token data type and length typically remain the same as the cleartext, and the token lookup table becomes the ‘key’ allowing the cleartext value to be retrieved from the token. Tokenisation does not have to use a mathematical process to transform the sensitive information into the token. There is no algorithm that can be used to derive the original data for a token. Instead, tokenisation uses a database, called a token vault, which stores the relationship between the sensitive value and the token. The real data in the vault is then secured, often via encryption.

PSEUDONYMISATION Pseudonymisation is a method to substitute identifiable data with one or more artificial identifiers, so called pseudonyms. The purpose is to render the data record less identifying while preserving data usability in analytics and processing. Pseudonymisation is defined as “the processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information.” The biggest difference between these two methods is that anonymisation places the processing and storage of personal data outside the scope of the GDPR. However, one may argue that true anonymisation is not possible. According to the deep learning authority Pete Warden.8 “The Anonymisation process is an illusion. Precisely because there are now so many different public datasets to cross-reference, any set of records with a non-trivial amount of information on someone’s actions has a good chance of matching identifiable public records.” Even if possible and done properly, anonymisation is an irreversible process which may devalue data is such a way that the organisation cannot longer perform their business process. The GDPR does recognise the need to preserve data utility and therefore use pseudonymisation as a means of compliance. Recital 29 of the GDPR aims, “to create incentives to apply pseudonymisation when processing personal data” and finds that, “measures of pseudonymisation should, whilst allowing general analysis, be possible”. These incentives appear in five separate sections of the Regulation, allowing pseudonymisation as a means for making data processing legal in cases which would otherwise not be lawfully possible. The effectiveness (and legality) of both anonymisation and pseudonymisation will always hinge on the ability to protect data subjects from re-identification. 8 https://www.oreilly.com/ideas/anonymize-data-limits


PROVEN EXPERTS IN DATA SECURITY Protegrity is the only data-first security solutions provider, trusted by enterprise security and data leaders in data-centric industries around the world. For more than 15 years, Protegrity’s laser-like focus on data security has set the standard, and its innovative approach is unmatched in its depth and breadth, protecting sensitive data in motion, in use and at rest. Protegrity partners with customers to secure the ever-changing data landscape through continuous innovation. Its proven approach to scalable, data-first security allows customers to optimise their use of data for greater business impact throughout the enterprise, while ensuring complete data privacy and regulatory compliance. With Protegrity, enterprises can embrace a data-first security posture that enables a customer-first approach to innovation, service, and leadership. Protegrity is headquartered in Stamford, Connecticut USA, with regional offices around the world.

To discuss further please get in touch with: Lee Chay Lip, Account Executive – Asia Pacific T: +65 9147 9384 E: chaylip.lee@protegrity.com Protegrity Singapore, 9 Raffles Place, Level 6 Republic Plaza 1, Singapore, 048619

www.protegrity.com Corporate Headquarters: Protegrity USA, Inc.

Protegrity (Europe)

333 Ludlow Street, South Tower, 8th Floor

Suite 2, First Floor, Braywick House West, Windsor Road

Stamford, CT 06902, USA

Maidenhead, Berkshire SL6 1DN, United Kingdom

Phone: +1.203.326.7200

Phone: +44 1494 857762


Turn static files into dynamic content formats.

Create a flipbook
Protegrity Privacy by Design Report by 18 Design - Issuu