<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Immutable kBlog: thoughts on data integrity &#187; Data Integrity</title>
	<atom:link href="http://www.kinamik.com/blog/tag/data-integrity/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kinamik.com/blog</link>
	<description>thoughts on security, data integrity, GRC and other security-related issues.</description>
	<lastBuildDate>Mon, 19 Apr 2010 09:18:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Data Integrity: the ticking time bomb</title>
		<link>http://www.kinamik.com/blog/data-integrity-the-ticking-time-bomb/</link>
		<comments>http://www.kinamik.com/blog/data-integrity-the-ticking-time-bomb/#comments</comments>
		<pubDate>Tue, 19 May 2009 10:23:02 +0000</pubDate>
		<dc:creator>Rob</dc:creator>
				<category><![CDATA[Data Integrity]]></category>

		<guid isPermaLink="false">http://www.kinamik.com/blog/?p=58</guid>
		<description><![CDATA[I&#8217;ve read a great post on David Lacey&#8217;s blog. Very clearly, he points out how most people and organizations are forgetting that information security is based is a three-pillar house (Availability, Confidentiality and Integrity, or CIA).
Availability was the main focus some years ago. Denial-of-service was the main worry, and business continuity was the focus of [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve read a great post on <a href="http://www.computerweekly.com/blogs/david_lacey/2009/05/the_age_of_integrity.html" target="_blank">David Lacey&#8217;s blog</a>. Very clearly, he points out how most people and organizations are forgetting that information security is based is a three-pillar house (Availability, Confidentiality and Integrity, or CIA).</p>
<p>Availability was the main focus some years ago. Denial-of-service was the main worry, and business continuity was the focus of organizations. Then came the turn for confidentiality, and encryption became something that was -almost- everywhere. The impacts of a loss in availibility is big; the impact of a loss of confidentiality is bigger&#8230; and scarier.</p>
<p>But now comes the time for data integrity. Right now, few decision-making minds in organizations focus on that, or care about it. But still, the impact of a loss in data integrity is -and here we agree with Mr. Lacey- huge. What if somebody changed the data -intentionally or not? Results can go from from undermining the people&#8217;s (think about the recent alleged <a href="http://voices.washingtonpost.com/securityfix/2009/05/hackers_break_into_virginia_he.html" target="_blank">attack by a hacker to the Virginia Health Professions Database</a>) or even fraud (think about the <a href="http://www.kinamik.com/blog/satyam-computers-indias-enron-wall-of-shame/" target="_blank">Satyam Computers</a>&#8216; case.</p>
<p>And it gets darker. The problem comes not only by safeguarding integrity, but also to the long and painful process of recovering from one of this attacks: how to know exactly which data is trustworhty (i.e. hasn&#8217;t been tampered with) and what is not?</p>
<p>It is surprising that currently there is not a big concern about this. We are guessing that unfortunately this concern will come when it is too late, and there are many breaches in data integrity and costs and consequences are there to remind us of its important. That is why, in David Lacey&#8217;s words,  it a time-bomb, waiting to explode.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kinamik.com/blog/data-integrity-the-ticking-time-bomb/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Defending on data integrity attacks</title>
		<link>http://www.kinamik.com/blog/defending-on-data-integrity-attacks/</link>
		<comments>http://www.kinamik.com/blog/defending-on-data-integrity-attacks/#comments</comments>
		<pubDate>Mon, 02 Mar 2009 08:59:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Data Integrity]]></category>

		<guid isPermaLink="false">http://www.kinamik.com/blog/?p=46</guid>
		<description><![CDATA[We&#8217;ve already mentioned that data integrity is going to be the next big threat. Well, Sarb Sembhi,  president of the London chapter of ISACA, also thinks like that.
In this very intresting short article, Mr. Sembhi points out something many people think: there are many more attacks than the ones disclosed to the public. He also [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve already mentioned that data integrity is going to be <a href="http://www.kinamik.com/blog/integrity-the-future-threat/" target="_blank">the next big threat</a>. Well, Sarb Sembhi,  president of the London chapter of ISACA, also thinks <a href="http://www.computerweekly.com/Articles/2009/02/16/234824/how-to-defend-against-data-integrity-attacks.htm" target="_blank">like that</a>.<br />
In this very intresting short article, Mr. Sembhi points out something many people think: there are many more attacks than the ones disclosed to the public. He also points out that, tied with the economic climate we currently have, several high-profile fraud cases are being discovered (and we think that unfortunately there are many more to come). Although not directly linked, he implies also that high-value frauds and data integrity attacks are closely related. The likeliness of data integrity being part of these data manipulations increases as the total value of the fraud gets higher; hence, it wouldn&#8217;t be wrong to assume that -again- the lack of proper data integrity protection tools certainly doesn&#8217;t help preventing this type of cases in organizations.</p>
<p>We are working for showing Mr. Sembhi that we are what he misses: a data integrity protection solution aimed at protecting every type of data.</p>
<p>In the meantime, he mentions a fact as true as the sky is blue: it all starts with putting proper procedures in place. For reducing the organization&#8217;s exposure to data integrity attacks (and to high-value frauds), Mr. Sembhi mentions:</p>
<ul>
<li>&#8220;Create policies and procedures for data quality and data integrity</li>
<li>Create policies and procedures to identify the extent of the problem and record incidences of data integrity compromises and suspected incidents of fraud</li>
<li>Ensure information assets are correctly valued, (including configuration and log files, and meta data)</li>
<li>Undertake threat assessment of valued data</li>
<li>Take a risk management approach to protecting data integrity</li>
<li>Ensure adequate protection of all data that is relied upon for investigatory purposes</li>
<li>Include data integrity protection as part of security awareness programme&#8221;</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.kinamik.com/blog/defending-on-data-integrity-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BSI 10008 &#8211; Another proof that integrity is the next big thing</title>
		<link>http://www.kinamik.com/blog/bsi-10008-another-proof-that-integrity-is-the-next-big-thing/</link>
		<comments>http://www.kinamik.com/blog/bsi-10008-another-proof-that-integrity-is-the-next-big-thing/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 10:08:50 +0000</pubDate>
		<dc:creator>Rob</dc:creator>
				<category><![CDATA[Data Integrity]]></category>
		<category><![CDATA[Laws and regulations]]></category>
		<category><![CDATA[e-discovery]]></category>
		<category><![CDATA[BSI 10008]]></category>
		<category><![CDATA[legal admissibility]]></category>

		<guid isPermaLink="false">http://www.kinamik.com/blog/?p=18</guid>
		<description><![CDATA[The British Standards Institution (or BSI) has recently published the BSI 10008, a new standard that focuses on the evidential weight of electronic information. It establishes up a set of requirements organizations should follow in their data management procedures for ensuring&#8230; yes, you got it: the integrity of information.
The new standard&#8217;s name is quite self-explanatory: [...]]]></description>
			<content:encoded><![CDATA[<p>The British Standards Institution (or <a href="http://www.bsigroup.com/" target="_blank">BSI</a>) has recently published the BSI 10008, a new standard that focuses on the evidential weight of electronic information. It establishes up a set of requirements organizations should follow in their data management procedures for ensuring&#8230; yes, you got it: the <strong>integrity </strong>of information.</p>
<p>The new standard&#8217;s name is quite self-explanatory: &#8220;Evidential weight and legal admissibility of electronic information. Specification&#8221;. As the <a href="http://www.bsigroup.com/en/Shop/Publication-Detail/?pid=000000000030191165" target="_blank">BSI website states</a>, &#8220;legal admissibility concerns whether or not a piece of evidence would be accepted by a court of law. To ensure the admissibility, information needs to be managed by a secure system throughout its lifetime (which can be for many years). Where doubt can be placed on the information, the evidential weight may well be reduced, potentially harming the legal case&#8221;. The BSI 10008 is aimed therefore to ensure that any piece of electronic information used in a Court of Law has the maximum evidential weight.</p>
<p>There are many interesting aspects here. First, it shows the need of clearly establishing  guidelines and a common framework for how to deal with electronic data and digital evidence. And second -but no less important- it outlines how <strong>data integrity</strong> is a key aspect in information management.</p>
<p>We just bought a copy of the standard. We&#8217;ll read it and publish some thoughts&#8230; Stay tuned.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kinamik.com/blog/bsi-10008-another-proof-that-integrity-is-the-next-big-thing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
