Can you trust data-recovery service providers?
- 12 January, 2012 07:25
- Comments
Data-recovery service providers are supposed to be saving important data for you when something goes wrong -- a drive crashes or storage device is dropped, and no backup is available. But do you trust them with the important data you let them recover or could they actually be a source for a data breach?
Security roundup: DoD revving up cyber-defense for 2012
A survey of 769 IT professionals published this week finds those surveyed need to find out more about the third-party data-recovery services their organizations use. For example, according to the survey, 67% felt that encryption they had in place protected their organizations from data loss or theft during the data recovery process. But encryption keys are often handed over to the third-party data recovery service provider as part of the process, according to the study done by Ponemon Institute.
Ponemon's "Trends in Security of Data Recovery Operations" report says of the 87% of survey respondents who said their organization had at least one data breach in the past two years, "21% say the breach occurred when a drive was in the possession of a third-party data service provider."
The Ponemon survey suggests IT professionals may be a little in the dark. Thirty-two percent of the IR professionals admitted they were unclear about the vetting process for selecting the data-recovery service provider, and 11% outright declared it to be "poor." Another 25% judged it "fair," and only 32% deemed it "excellent" or "good." The speed and success of the provider were the most important factors for the survey's respondents, but little consideration was given to confidentiality and security. The survey was sponsored by DriveSavers Data Recovery.
The IT desktop and helpdesk managers were the most responsible for selecting the data-recovery service providers, but only about half of the survey's respondents said IT security is involved. Final selection of the vendor is often based on a background check of the vendor and analyzing the vendor's storage-device disposal procedures.
In the survey, less than half said they do ask the data-recovery service provider to adhere to some sort of security guidelines. The most requested security was encryption for data files in transmit mentioned by 28%, a Certified ISO (Class 100) "cleanroom" by 23%, as well as a demand of evidence of safe handling of devices by 23%. But only 16% said they demanded proof-of-custody documentation, though 80% said they should require it. Less than a third were confident they'd be notified if a data breach resulted from errors or mistakes.
Cloud service providers also figured into the survey, with the Ponemon Institute asking survey respondents how much was known about their cloud-service provider's data-recovery practices, if any. Fifty-five percent said their organization does use a cloud-service provider, but only 19% expressed any degree of confidence that if the cloud-service provider engaged a third-party data-recovery vendor, it would let them know.
Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security.
Read more about wide area network in Network World's Wide Area Network section.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Should you share breach information? : NetworkWorld.com Community
- Security roundup: DOD revving up cyber-defense for 2012; Microsoft to have big January Patch Tuesday
- Corporate data breach average cost hits $7.2 million
- Amazon adds more spots for connecting directly to its cloud
- LAN & WAN Research Center - Network World
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Pfizer's Future Depends on IT Transformation
-
Pfizer's Future Depends on IT Transformation
-
Apple aims iPads at High Schools
-
Top 10 Mistakes in Data Centre Operations: Operating Efficient and Effective Data Centers
For years, the data centre industry has accepted that human operational error, not poor data centre design or engineering, is the number one cause of data centre downtime. Now is the time for companies to evaluate their data centre operations programs. They must be able to clearly articulate operational requirements and design an operations program based on the risk profile of the data centre. However, the road to creating an industry-best operations program will not be easy, especially for those companies whose core expertise is not in business critical facilities. Read on. -
So Long, Silos: Why Multi-Domain MDM Is Better For Your Business
Say “so long” to silos. This white paper explains why a multi-domain MDM solution is far better than single-domain, single-focused point solutions. You’ll learn what to look for in a multi-domain solution so you don’t outgrow it or are forced to purchase multiple products down the road. You’ll also get tips on how to select a multi-domain solution that can lead to multiple benefits over many years. The age of multi-domain MDM is here. See why you should say “hello” to it! -
Oracle Business Process Analysis Suite
Careful analysis and continuous optimization of business processes delivers real competitive advantage. Conversely, a random approach to process design negatively impacts a company’s bottom line. This insight is one reason successful companies adopt business process management (BPM) as a way of aligning their business processes with business and customer requirements. Success with BPM eliminates the gap between business strategy and implementation. Business users are empowered to participate in all stages of the business process lifecycle. Closed-loop integration between modeling, execution, and monitoring enables continuous and holistic business process improvement.
-
Mastering Windows 2000 Registry
-
Operating Systems Concepts with Java 6E Wileyplus/WebCT Standalone Card
-
The Csslp Prep Guide
-
PCs for Dummies Quick Reference, 4th Edition
-
Goal-oriented Requirements Engineering - From System Objectives to UML Models to Precise Software Specifications
-
C++ and the Object-oriented Paradigm
-
CD & DVD Recording for Dummies, 2nd Edition
-
Photoshop 7 Bible, Professional Edition
-
Comptia A+ Complete Fast Pass (Exams 220-601/602/603/604)








Comments
Post new comment