Static Data Masking (SDM)
Proven, persistent protection for data at rest
Static Data Masking
Persistent data masking, or static data masking (SDM), is the primary method for protecting specific data elements at rest. These „elements“ are typically database column or flat file field values that are considered sensitive. These fields may contain personally identifiable information (PII), protected health information (PHI), primary account numbers (PAN), trade secrets, or other private values.
SDM is used to prevent data breaches, provide secure test data, and comply with data privacy laws. Compare it with Dynamic Data Masking (DDM), which selectively masks sensitive values for database applications.
The „Starting Point“ security product IRI FieldShield, IRI DarkShield, IRI CellShield, or the IRI Voracity platform, which includes all functions — offer more Data discovery– and SDM features for more Data sources like any other data masking tool. This now also includes a state-of-the-art assistant to Risk assessment from Re-IDs. Referential integrity, or deterministic data masking, is achieved through the automatic application of consistent masking functions.
The available functions per field/column include:
multiple, NSA Suite B and FIPS-compliant encryption (and decryption) algorithms, including format-preservingEncryption
·SHA-1 and SHA-2Hashing
ASCIIIde-ID Bitstream encryption
Datablur and generalize
Blacken(String masking)
reversible and irreversiblePseudonymization
Expression (Calculation / Shuffle) Logic
conditional / partial filtering (omission)
custom value replacement
ByteShifting– and substring functions
Tokenization(for PCI)
You can also execute your own external data masking functions. This way, you can invoke a custom field protection instead of an integrated function at runtime.
Whether built-in or custom, you can conditionally apply functions to specific rows or columns and save and reuse them across tables via protection rules that you define. It is also possible to integrate these functions into a Dynamic Data Masking (DDM) context to apply.
Create, execute, and manage your data masking jobs in a free and state-of-the-art GUI, based on Eclipse™, or use the same, simple, self-documenting 4GL metadata that defines your data layouts and protections in a command-line environment.
If you have sensitive data in Excel, take a look at IRI CellShield CellShield supports many of the same encryption, redaction, and pseudonymization features as FieldShield.
If you have sensitive data in unstructured text, log, MS Office, Parquet, or PDF files, or in semi- or unstructured RDB columns or NoSQL DB collections, you should IRI DarkShield view. The DarkShield API supports all, and the DarkShield GUI supports at least half of the static data masking features in the categories above. The same deterministic (consistent) data masking results apply across all IRI Shield tools, so you can preserve data integrity (and referential integrity) across all enterprise data sources protected by them.
Did you know?
FieldShield is the award-winning, purpose-built static data masking product for databases and flat files, built on Eclipse and powered by IRI CoSort. FieldShield – along with DarkShield and CellShield – is also part of the IRI Data Protection Suite and all products are also in the IRI Voracity data management platform included.
Voracity users can perform these static masking functions along with data discovery, integration, migration, governance, and analytics operations. For example, they can cleanse, encrypt, and sort data for secure mass DB loads simultaneously, mask data migration/replication or subsetting targets, and create a delta report or ETL job that also de-identifies fields.