Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
20% Of 'Broadly Shared' Data Contains Regulated Info
Newest First  |  Oldest First  |  Threaded View
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
10/28/2014 | 12:15:01 PM
Re: The other Elastica
Netskope reported some recent research recently on the explosion of sharing activity recently. The data revealed sharing activity that went beyond what people typically think of sharing via cloud storage -- such as enterprise financial, human resources, project management and productivity apps . Interesting data. More here in a Dark Reading commentary  for whoever is interested. 
JessicaMorrison
50%
50%
JessicaMorrison,
User Rank: Apprentice
10/28/2014 | 10:44:40 AM
Re: The other Elastica
I love the band Elastica! The songs Connection and Car Song consisted of many playlists and burned cds Sara, you have great taste in music. :)

Shadow IT is definitely a concern we've seen with many customers and with constant changes to regulatory compliance like PCI DSS and HIPAA, Shadow IT will need to be controlled and monitored closley but in a way that doesn't inhibit the business either. We want IT to be seen as a business enabler and operating in this environment is possible so long as IT is assessing, auditing and protecting data on the move. It also helps to have compliance and security awareness training in place that stripes people, process and techonology. All too often we see human error contributing to failed audits or breaches, which is unfortunate because most people are well intended. A littie information on what is considered sensitive data can go a long way. 

Thanks for covering a great topic.

Jessica Morrison, GRC Sr Product Marketing Manager, Dell
Stratustician
50%
50%
Stratustician,
User Rank: Moderator
10/24/2014 | 2:00:27 PM
Re: The other Elastica
Nice, it's been awhile but I did own their CD back in the day. 

Shadow Data is indeed a huge concern, and most employees are probably guilty of at least one count of oversharing data that probably shouldn't be even stored in any cloud storage offering.  I've always been a fan of whitelabelling, putting data tags to hopefully reduce the ability for misuse of data, but the reality is that there ar eso many ways to circumvent systems and policies that this will always seem to be a headache for IT and security folks.
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
10/23/2014 | 7:54:54 PM
Changing the Format of Sensitive Data
While these statistics for over-shared data may appear small, there is another issue that is hinted at here not often talked about.  That is, the format of the data.  What makes certain types of data so attractive to share is the format used to store it.  For instance, the MP3 is so easily passed amongst users that millions of songs exchange hands everyday without a second thought.  The same is true of books in PDF format.  The nature of the "file" as we know it today, whether that is on a UNIX or Windows file system, contributes to this very over-sharing.

Now consider the alternative.  For all types of data that are regulated by nature, there is an opportunity to standardize how that is delivered, stored and viewed to not include "files", thus causing over-sharing to no longer be possible.  If not a file, then what?  Well, we shall see...  Add on top of this variable encryption and decryption schemes and biometric-based access and you could all but eliminate the misuse of regulated information.  Too expensive to implement?  I suspect that depends upon how much regulated data integrity is worth to you, and how much it costs every year to deal with cases of over-sharing.  

 

 
Thomas Claburn
50%
50%
Thomas Claburn,
User Rank: Ninja
10/23/2014 | 6:43:18 PM
Re: The other Elastica
If we're going to highlight British bands of yore, I'd vote for Shriekback (which is still around and about to release its 13th recording).

www.youtube.com/watch?v=6bMM61Y5CEU
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
10/23/2014 | 4:25:44 PM
The other Elastica
I know this has nothing to do with data security, but does anyone remember the British band Elastica? I listened to their first album incessantly in 1995. www.youtube.com/watch?v=ilKcXIFi-Rc


Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Take me to your BISO 
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-23369
PUBLISHED: 2021-05-10
In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3.
CVE-2020-23370
PUBLISHED: 2021-05-10
In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.
CVE-2020-23371
PUBLISHED: 2021-05-10
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web script or HTML via the movieName parameter.
CVE-2020-23373
PUBLISHED: 2021-05-10
Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.
CVE-2020-23374
PUBLISHED: 2021-05-10
Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.