Data protection
Apply role-based access controls to sensitive data
Challenges
Your company handles personally identifiable information (PII). Your efforts to Data management must prevent the types of data disasters that in Privacy Rights Clearinghouse to be published. They must comply with industry and government privacy regulations.
Since you cannot eliminate PII, you must discover, protect, and verify that you have protected it. Then you also need to monitor and address data risks in the future.
At the time of protection, technological choices are difficult. Conventional encryption of entire databases, files, hard drives or devices is inefficient (especially in terms of volume), restricts access to non-sensitive data, and is subject to complete disclosure through a single password breach. Many data masking methods are insecure, complex, expensive, or render the protected data unusable for testing.
With current methods, you also won't get support for:
- Assistance with searching, extracting, classifying, or applying rules to data that meets PII criteria.
- An audit trail showing how you managed the risk to force a costly validation.
- A separation of encryption and key management (should be questioned)
- The ability to apply multiple security measures to multiple data sources simultaneously.
- The possibility of combining data protection with other data processing operations.
„Solutions that enable file, database, and application-level encryption offer the highest level of security and allow authorized individuals easy access to information. Decentralized encryption and decryption offer more performance and require less network bandwidth, increase availability by eliminating sources of error, and ensure better protection by transferring data more frequently yet securely.“
Gary Palgon, Enterprise Systems Journal
Solutions
IRI Data Protector Suite „-shield“ products like IRI FieldShield — as well as the SortCL program in IRI CoSort Packages and the IRI Voracity Platform — support data masking features on Field of vision for data masking functions for data in tables and files. They protect PII and:
- Find and classify PII, so that global masking rules can be applied later or at the same time
- Use the function toData masking (Replace, Encrypt, Pseudonymize, Hash, etc.) that you choose for each data class, while maintaining referential integrity
- Maintaining data realism through format-preserving encryption, pseudonymization, referential integrity, etc.
- Save time, money, and hassle by not masking sensitive data
- Enhance security by applying different functions to different data sources and elements
- Efficiency Increase through the Combination of Data Protection with Data Transformation and Reporting
- Review of compliance with multiple data protection laws with re-identification risk assessment and query-ready audit logs of protection orders
- Sending compliant data to applications, reports, databases, the cloud, and BI/analytics destinations
- Data Loss Prevention (DLPImplement the program properly and without excessive complexity
The IRI CellShield-Software does the same for PII in Excel spreadsheets and IRI DarkShield detects this for PII hidden in unstructured text, documents, NoSQL databases, and image files.
Non-recoverable functions
Irreversible data masking options in IRI software include:
Blackening or omission
Anonymization (Blur or Fill)
Randomization
Pseudonymization (by chance)
Hashing or Tokenization
Custom Field functions
Delete
Recoverable features
Among the options for reversible data masking in IRI software are:
Encryption (Decoding)
Bit-interleaving less sure
Binary encoding Decoding
Pseudonymization (about Restore Set)
Expression / String Logic
Anonymous Test Data
IRI RowGen uses the same Metadata like FieldShield and Voracity to randomly generate realistic test data column by column. While this data is being synthesized, RowGen can also uniquely transform this data and report on it at the same time!
Use RowGen to create secure, referential integrity-free test data for databases and files. without creating production data.