Verification of conformity

Prove that you have protected the right data in the right way

Challenges

Other data protection laws - such as those listed in this section - in the US, Europe and other international jurisdictions are currently being passed and enforced. CISOs and data governance teams responsible for protecting vulnerable data must also demonstrate that they are protecting that data in the right places and in the right ways. localized and protected in the right way have.

Data Loss Prevention (DLP) systems and Data masking software can discover and de-identify personally identifiable information (PII). How well do you document your search results and actual masking procedures? How easy is it to find and change certain safeguards if something needs to be redone or done differently? How can you measure and mitigate the risk of re-identification based on quasi-identifying data?

Solutions

Extensive scan logs and dashboard reports from the data profiling and sensitive data detection modules included in all IRI data masking programs are available for detection control. For example, there are scan-specific text reports as well as visualizations like this one:

IRI schema data class search results

 

For masking operations, all data protection measures are documented in the self-documenting, human-readable job scripts, mapping diagrams or configuration files, or audit logs for IRI FieldShield-IRI DarkShield, IRI CellShield EE (all of which are also in the IRI Voracitydata management platform).

In the case of FieldShield, the audit trail contains each job script showing the protection technique(s) applied to each field in each table or file processed. Source-to-target mapping diagrams quickly show the same changes with orange connectors, and the visual representations of the jobs are handy images to share.

This XML audit log also contains other order metadata, such as the:

  • Protection library function(s) used
  • Encryption keys or De-ID codes
  • Input and output tables or files
  • User who executed the job
  • Start and end times of work
  • Number of processed data records

 

 

To prevent data protection violations, you can check your orders to confirm the protection of the output fields by a developer before execution.

Masking the SSN field in a payroll feed, for example, is a matter of connecting to your sources (or existing jobs) and clicking through a new job wizard or changing existing parameters in a dialog box or script. Some of the functions you can apply (ad hoc or usually) are:

  • Encryption and decryption
  • Anonymization through pseudonymization
  • Data masking
  • De-identification and re-identification
  • Field blackening

 

 

As a compliance officer, you can see the protection(s) in any self-documenting job script or diagram. Once approved, the job can be saved or executed on any local or remote server running the IRI data masking file.

After execution, the job script can be isolated or shared and used with, for example EGit modified or protected to enable reliable reuse in production. FieldShield also includes a Re-ID risk assessment module are provided to statistically measure the likelihood of linking a dataset to an individual based on the unmasked quasi-identifying (demographic) attributes in their dataset. Other anonymization techniques such as blurring and bucketing to generalize this data to reduce re-identification risk but preserve the utility of the data for research and marketing purposes are included (see HIPAA and FERPA tabs above).

The proxy-based dynamic data masking system available with IRI FieldShield is a front-end in a web application called SQL#. All database activity intercepted via the associated JDBC SQL Trail driver is recorded in an active logging environment and can be exported.

In the case of IRI DarkShield an even more sophisticated dashboard is provided to display found data versus masked data:

 

 

This data can also be reviewed in machine-readable search and masking artifacts in the IRI Workbench or used for further analysis and Action in SIEM tools such as Splunk Enterprise Security exported become.

In the case of IRI CellShield EE both the data discovery results and the audit trails of the masking operations are provided in Excel and linked for export to Splunk and Datadog.

Further information on IRI data forensics in general can be found on this page. Also take a look at the Options for data lineage on this page.