|
Threat
Agent
|
Example or Scenarios
|
Action
for Prevention
|
|
Document
printing
|
A
sales representative planning to quit tries to print out customer records
from the SAP database for future use. This could cause a data breach that
must be reported publicly.
|
The
printing activity from the SAP application should be blocked.
|
|
External
storage device
|
A contractor
attempts to save source code to an iPod or USB drive.
|
The action
should at a minimum be monitored and most likely blocked depending on policy.
|
|
Copy/Paste
|
A
non-HR employee attempts to copy employee data from the Oracle HR database
into a Word document. This could lead to a violation of employee privacy
|
The
paste should be blocked
|
|
Screen
capture
|
An administrator
tries to copy an on-screen display of sensitive data using the “print screen”
command
|
The “print
screen” action should
be blocked
|
|
Web
mail or web posting
(forums,
blogs, wikis)
|
An
accountant tries to send controlled financial information in an email (body
or attachment) from a personal web mail account, or mistakenly posts it to an
external web site
|
As
soon as the user attempts to send the message or post the content, it should be
blocked (before it is leaked)
|
|
Inappropriate
internal
transfer
|
A sales engineer
attempts to send multiple customer records to a support engineer. The company
has a policy on straining customer data transfer outside each specific domain
to a single record at a time
|
The system
should detect the mail or instant message with multiple records, and block
the transfer
|
|
Encryption
|
An
executive sends merger documents to legal counsel. Policy dictates it should
be encrypted, but the message is being sent in plain text
|
The
email and documents should be encrypted before transfer
|
|
Guest
laptops
|
A visitor uses a
laptop to connect to the corporate LAN and attempts to forward sensitive
information via web mail or email
|
The message
should be blocked
|
|
Mobile
PDAs
|
An
executive uses his BlackBerry and mistakenly forwards an email
containing
sensitive product roadmap dates
|
The
message should be blocked from leaving the enterprise
|
|
Roaming
users
|
While at a
conference, a developer tries to transfer source code from
a laptop to a
USB drive or CD
|
Usage policies
should remain in
force, even
though the system
is disconnected
|
Thursday, 29 January 2015
Different scenerios or example of confidential data leakage
Labels:
leakage