seclore infosource - security concerns in outsourcing

27
Security concerns in outsourcing An Introduction to Seclore InfoSource Abhijit Tannu CTO www.seclore.com

Upload: gilberteric-eric

Post on 12-Mar-2016

219 views

Category:

Documents


0 download

DESCRIPTION

http://www.seclore.com/ : The webcast looks at typical information security issues faced in outsourcing, their causes possible remedies. It also introduces Seclore InfoSource, a secure outsourcing technology for “end to end encryption” of information shared with outsourcing partners. Seclore InfoSource introduces an easy to integrate method in existing business processes and involving minimum changes in infrastructure.

TRANSCRIPT

Page 1: Seclore InfoSource - Security Concerns in Outsourcing

Security concerns in outsourcingAn Introduction to Seclore InfoSource

Abhijit TannuCTO

www.seclore.com

Page 2: Seclore InfoSource - Security Concerns in Outsourcing

The problem

Page 3: Seclore InfoSource - Security Concerns in Outsourcing

The problem

Page 4: Seclore InfoSource - Security Concerns in Outsourcing

The problem

Page 5: Seclore InfoSource - Security Concerns in Outsourcing

The problem

Page 6: Seclore InfoSource - Security Concerns in Outsourcing

The problem

In 2010, the total size of the outsourcing market is expected to be about USD 154B

~USD 1.9B will be spent on proactive and reactive actions on information breaches

An average breach costs an enterprise USD 6.75 M in direct costs

Page 7: Seclore InfoSource - Security Concerns in Outsourcing

The risks - Human

Each person in the chain of outsourcing process handoffs represents a “risk”

*High man power churn typical to the industry

=Mother of all HR problems !!

This element of risk is indispensable, intelligent, adaptive and prone to greed !

Page 8: Seclore InfoSource - Security Concerns in Outsourcing

The risks – Legal and compliance

Legal cover for malfunction for any of the risks is critical

Outsourcing process is typically under compliance norms of various country specific norms,

compliance frameworks and cross border data flow agreements

Liability is largely spread across multiple entities and reputation risks are not covered

Insurance is at-best, high cost !

Page 9: Seclore InfoSource - Security Concerns in Outsourcing

The risks - technology

Information through the lifecycle of creation – storage – transmission – use – archival & deletion

represents one of the biggest risks

Multitude of information systems with hand offs have shown themselves to be prone to breaches

Controls are typically built into individual applications

Page 10: Seclore InfoSource - Security Concerns in Outsourcing

Information exchange in outsourcing

• Remote application access is provided• Vendor may be part of same network / domain• Vendor may be complete disconnected.

ENTERPRISE

Outsourcing partner

FirewallVPN Network

Outsourcing partner

Disconnected Network

Outsourcing partner

VPN

Remote Access

Page 11: Seclore InfoSource - Security Concerns in Outsourcing

The underlying issues

Share it = It becomes his (also)Usage and access control separation is not possible

Share it once = Share it foreverNo possibility of information “recall” if relationships change

Out of the firewall = Free for allOnly legal contracts protect information outside the

“perimeter”

Page 12: Seclore InfoSource - Security Concerns in Outsourcing

Illustration

BankBPO

BPO Employees doing data entry

Bank Employee

Kay Bank outsource it’s data entry work to a remotely located business partner IntServices Pvt Ltd

Page 13: Seclore InfoSource - Security Concerns in Outsourcing

Illustration

BankBPO

BPO Employees doing data entry

Bank Employee

Certain documents are scanned and image files are sent by a bank employee to the business partner via a secured FTP connection.

Page 14: Seclore InfoSource - Security Concerns in Outsourcing

Illustration

BankBPO

BPO Employees doing data entry

Bank Employee

Different employees process the scanned image files to enter data into excel or database files. These files are sent back to bank via secured FTP.

Page 15: Seclore InfoSource - Security Concerns in Outsourcing

Illustration

BankBPO

BPO Employees doing data entry

Bank Employee

Confidential data may be leaked by one of the employees to a telemarketer.

Telemarketer

Page 16: Seclore InfoSource - Security Concerns in Outsourcing

A new concept in secure collaboration

RightLocation

RightTime

RightAction

RightPerson

Users from bank as well as outsourcing partner can access protected information provided it is -

• Right Person : Only pre-identified authorized persons / groups

• Right Action : Action performed by the processing application – View / Edit / Print / Full Control

• Right Time : Within the stipulated time

• Right Location : Only pre-identified trusted machines / applications

Defined by the enterpriseOutsourcing

partner

Page 17: Seclore InfoSource - Security Concerns in Outsourcing

Illustration - AfterIllustration - After

BankBPO

BPO Employees doing data entry

Bank Employee

Kay Bank outsource it’s data entry work to a remotely located business partner IntServices

Page 18: Seclore InfoSource - Security Concerns in Outsourcing

Illustration - AfterIllustration - After

BankBPO

BPO Employees doing data entry

Bank Employee

Certain documents are scanned and image files are protected & sent by a bank employee to the business partner via a secured FTP connection.

Page 19: Seclore InfoSource - Security Concerns in Outsourcing

Illustration - AfterIllustration - After

BankBPO

BPO Employees doing data entry

Bank Employee

Different employees process the scanned image files to enter data into excel or database files. These files are sent back to bank via secured FTP.

Page 20: Seclore InfoSource - Security Concerns in Outsourcing

Illustration - AfterIllustration - After

BankBPO

BPO Employees doing data entry

Bank Employee

Telemarketer

In case anyone attempts to make copies of the information and send it to an unauthorized user / location, the information becomes inaccessible

Page 21: Seclore InfoSource - Security Concerns in Outsourcing

Illustration - AfterIllustration - After

BankBPO

BPO Employees doing data entry

Bank Employee

After legitimate use, Kay bank can ensure that information shared with or generate by Intservices is destructed

Page 22: Seclore InfoSource - Security Concerns in Outsourcing

Introducing Seclore InfoSource

A technology for defining and implementing usage policies on information before sharing

Granular usage policies can define …Right person, Right action, Right time & Right location of usage

Policies are persistent and travel with the information wherever it goes

Page 23: Seclore InfoSource - Security Concerns in Outsourcing

Introducing Seclore InfoSource

ENTERPRISE OUTSOURCING PARTNER

“Hot Folder” with pre-defined permissions for usage

Email, Web, FTP, Fileshare

Processing

Application

Page 24: Seclore InfoSource - Security Concerns in Outsourcing

Introducing Seclore InfoSource

Outsourcing Partner

Source ApplicationProcessing Application

Enterprise

Processing ApplicationHot Folder

Anywhere else

Page 25: Seclore InfoSource - Security Concerns in Outsourcing

About …About …Seclore is a high growth information security product company

focussed on providing Security without compromising collaboration

Seclore’s flagship product Seclore FileSecure is used by More than 1 million users & some of the largest enterprises

. . .

Page 26: Seclore InfoSource - Security Concerns in Outsourcing

26

What customers say about us …What customers say about us …

Senior Vice President and CISO, HDFC Bank.

"In today’s world, where the boundaries of the organisation’s functionality are disappearing, we are dependent on different business providers to process our customer information. Given that requirement, we still want to control how that information is used and processed by the service providers. Seclore’s technology has allowed us to do that." - Vishal Salvi, CISO

Page 27: Seclore InfoSource - Security Concerns in Outsourcing

27

Want to know more …Want to know more …

Website : www.seclore.com

Blog : blog.seclore.com

Email : [email protected]

Phone : +91-22-4015-5252