Data integrity, the next big threat

Data integrity

The answer is very few. And Avellanet has the numbers to quantify his thesis: "Of the 20 data integrity audits that I conducted just last year for clients, just one firm had a change control process that required data regression testing, and they'd just implemented it and weren't certain yet how to do it. So, we're making progress, but we've a long way to go."

In the big data/SaaS world, Lucas Moody, CISO, Palo Alto Networks, says it seems as if we've created a giant game of telephone, but the reality is all the parties engaged have a vested interest in ensuring the integrity of the game and the final outcome.

And while integrity in big data environments has been a debate in recent months, particularly in use cases involving massive compute operations, genetic research and clinical studies among others, the pollution or injection of small amounts of data are oftentimes inconsequential when dealing with large data sets, as the law of large numbers would indicate, Moody says. That said, in environments where data integrity is paramount, data at rest, data in transit and control around those who have the capability to manipulate data has to be considered in a comprehensive information security strategy, he says.

Protecting the integrity of big data is a much larger and more complex problem than that of traditional PII, says Michael Taylor, applications and product development lead at Rook Security. A single record of information about an individual may contain data like street address, date of birth and Social Security number, he points out. "In a big data context, a single user may generate many thousands of times that volume of data through their every day use of a website, app or service. This larger volume of data will typically be generated and piped through several different resources."

Verifying the integrity of data as it passes through multiple tools is where the increased complexity comes into play, he adds. "Ensuring that the data generated on the user application side has not been manipulated inadvertently or maliciously before arriving at the final data store requires external monitoring and sampling of the data in motion and at rest."

The state of data integrity is not very good, says Tavakoli. "We're in the early stages of understanding the implications of data integrity issues. While data engineering teams have been trained to cleanse data (throw some of it out because it lacks certain key fields) and normalize it, they have not been trained to look for signs of tampering with the data. It's akin to the early days of cybersecurity when there were weaknesses in the way code was developed and the SDL acronym hadn't been invented yet."

Akamai's Shaul says we have so many things to secure. Organizations need to take a holistic view of their data, he explains. "They must ask: Where is the sensitive information stored? How is it used, processed and transmitted? Who has access at each level – and more importantly, who should have access?"

"Security always starts with understanding your own estate and building a threat model that helps you understand what and where an attacker is likely to target," Shaul says.

 

Share it:
Share it:

[Social9_Share class=”s9-widget-wrapper”]

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

You Might Be Interested In

EU data protection watchdogs support stronger ePrivacy legislation

7 May, 2017

On 10 January 2017, the European Commission (EC) published its long-awaited proposal for an e-Privacy Regulation (ePR) to replace the 2002 …

Read more

Customers taking back control of their data from the Banks

25 Apr, 2017

2018 is likely to be a game-changing year for the banking and finance sector. As the General Data Protection Regulation …

Read more

How industry can protect privacy in the age of connected toys

7 Dec, 2016

As we enter the season of holiday shopping, many of the most popular children’s toys on the market are designed …

Read more

Recent Jobs

Senior Cloud Engineer (AWS, Snowflake)

Remote (United States (Nationwide))

9 May, 2024

Read More

IT Engineer

Washington D.C., DC, USA

1 May, 2024

Read More

Data Engineer

Washington D.C., DC, USA

1 May, 2024

Read More

Applications Developer

Washington D.C., DC, USA

1 May, 2024

Read More

Do You Want to Share Your Story?

Bring your insights on Data, Visualization, Innovation or Business Agility to our community. Let them learn from your experience.

Get the 3 STEPS

To Drive Analytics Adoption
And manage change

3-steps-to-drive-analytics-adoption

Get Access to Event Discounts

Switch your 7wData account from Subscriber to Event Discount Member by clicking the button below and get access to event discounts. Learn & Grow together with us in a more profitable way!

Get Access to Event Discounts

Create a 7wData account and get access to event discounts. Learn & Grow together with us in a more profitable way!

Don't miss Out!

Stay in touch and receive in depth articles, guides, news & commentary of all things data.