On 19 Jan 2007 08:57:13 -0800, [EMAIL PROTECTED] (Dave Kopischke) wrote: >So what happens when that disgruntled employee decrypts a tape and >downloads it to a USB memory stick and walks out the door with that ??? >Those memory sticks hold a lot of information and they're very small. At >some point, you've got to evaluate the situation for reasonableness and >call it good enough. > >I would also argue that the disgruntled employee scenario is a data theft, >not a data loss. Prosecute relentlessly or it will only get worse.
It seems that one part of security that isn't emphasized is to have a procedure that checks to see if such a crime has been committed. We can't do that by examining our data to see if they're missing - we have to monitor to see if they show up elsewhere. That might mean we keep tracer data in our database that are designed for this task. ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html