SlideShare a Scribd company logo
1 of 29
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Case Study:
Securing & Tokenizing Big Data
Dan Houser, CISSP-ISSAP-ISSMP CSSLP HCISPP
@SecWonk
Principal Security & Identity Architect
24-April-2014
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
AGENDA
Drivers for Big Data
Cardboard Bicycles
Challenging the Status Quo
Cardinal Big Data Security Model
Access Model
Lessons Learned
2
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Cardinal Health
30,000
plus employees
with direct
operations in 10
countries
60,000
sites delivered
to daily
3
*An estimate of the pro forma revenue for fiscal 2012 in accordance with generally accepted accounting principles
with adjustments expected to reflect each company as a stand-alone entity. The estimate is based on assumptions
that management currently believes are reasonable, but actual revenue may vary materially from the estimate.
Leading provider of products and services across the healthcare
supply chain with an extensive footprint across multiple channels
$108B
FY12 pro forma
revenue*
#21
on Fortune 500
list
86%
of hospitals in the
U.S. use our
products and
services
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Essential purpose
We are more than 30,000 people applying our
deep understanding of healthcare to deliver inventive
and meaningful solutions that help improve the
cost-effectiveness and quality of healthcare so our
customers can focus on patients.
4
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Essential role
We are the business behind healthcare
5
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
6
Hadoop Vision
Background
Cardinal Health is increasingly emphasizing the importance of advanced analytics
due to the financial benefits, competitive advantage and organizational effectiveness
enabled by the growing # of successes from our analytics initiatives.
Business Needs
To further advance Cardinal Health into a transformed company with analytics
prescribed actions*, increased ROI, reduced complexity, and improve our overall
efficiency, we need to optimize existing assets, accelerate adoption of learning
from existing success stories (and failures) and enable an affordable, scalable and
agile platform to meet business need of increased decision velocity as well as
trusted data attainability & usability.
* Transformed Company is defined in MIT/IBM Sloan 2012 research on Analytics as companies with rigorously data
driven decision making culture and with daily critical data insights and analytics prescribed actions
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
7
Hadoop Business Opportunity
• Provide the most cost effective capability to quickly react
to the changing business needs
• Leverage machine learning, pattern-recognition
capabilities across disparate datasets for deep data
analytics
• Support Cardinal Health’s Master Data Management plan
• Securely manage analytical data required for our clinical
analytics applications (including HIPAA data)
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
8
High-level Hadoop at Cardinal
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Cardboard Bicycles
Our Hadoop architecture is radical, and based on the
premise of the Cardboard Bicycle
Innovative
Consumable IT
Low-cost
Zero-touch model
Image courtesy: Cardboard Technologies http://goo.gl/ztWvR
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Internal use only
Criteria Conventional Hadoop
Fault Domain Server
(Toyota Camry)
Rack of servers
(Paper Bicycle)
Server repair Hours Days
Server Cost 19%
Storage Cost 3%
Cost/Analytical GB 1% of SAS 4% of Teradata
Performance Server Across Grid
Management Server Server Type
Admins/Server 100/1 1000/1
Uniqueness Every server unique All servers alike
Lifecycle 3 years Till it dies
Troubleshooting By Server (App) As a whole
Ability to Evolve Quarterly Daily (if needed)
Operating System Locally Installed Network Bootable In Memory
Unique Ideas
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
11
Risks & Mitigating Strategies
• Rapidly Evolving Open
Source Project
• Open model by default
• Massive data repository
• Inference can lead to
de-anonymization
• Data corruption
• Delayed adoption of new
features until vetted
• Data access controlled by
data owners group
• Adhoc access limited
• Not allowing any private,
HIPAA, or other controlled
data into the environment
without encryption/masking
• Creating replica of production
onto a backup cluster
Risk Mitigation
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
12
Hadoop Architecture
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Access
Nodes
13
Role-based Access Model
• Segmented access control to access/ control/ data nodes
• Active Directory groups
• Secure groups for data segmentation where sensitive
• Vintella Authentication using Kerberos
• Access Nodes can talk to Control Nodes, Control Nodes can talk to Data Nodes, User
restricted to Access Layer
Datameer
Admin
Data
Nodes
Users
Power Users
AD
MySQL
Sqoop
Hive
Flume
Control
Nodes
Developers
Data Owners
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
14
Security Model
• EA and Hadoop project team have implemented world-class
Hadoop security model
• Host-based firewalls on control & data nodes
– Locked down using iptables
– Block connections from unauthorized hosts
• Gold-image boot for data nodes
– No persistent OS / config data - continuous fresh, secure image
– Ease of security patching
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
15
Security Model
• Segregated VLAN on dedicated network switches
• Supported open source via Hortonworks
• Backup environment for data integrity (not DR)
• Segregated Prod, Tek, Integration, Backup environments
• Transaction, security and event logging
• Host-based file integrity monitoring
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
16
Security Challenges
• Information Classification continues to be difficult for IT
and business teams, particularly when otherwise
innocuous data is made sensitive in context.
• Anonymization patterns emergent – differing patterns
applied in source repositories
• No enterprise-wide cryptographic solution providing
format-preserving or context encryption
• Detection & Prevention of de-anonymization is a
problem for the industry, and also for us
• Data Governance within Hadoop team going 100mph
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.17
Decision Tree
Start
1.0
Input in
Cleartext?
Y
1.1
Can it be
Redacted?
Y
1.1.1
Redact/scrub the
data
SSN:111-22-3333 Ê
xxx-xx-3333
1.2
Can it be
tokenized?
N
Y
1.2.1
Tokenize the Data
SSN:123-45-6789 Ê
987-31-4929
2.0
Output in
Cleartext?
1.3
Must encrypt
N
N
3.0
Does data always
remain encrypted?
N
Y
Y
3.1
No cryptography
needed for data at
rest
3.2
Need to decrypt
and encrypt
within solution
Go to 1.1
N
1.3.1
Is Data shared
Externally?
Y
1.3.1.1
Use File / Folder
Level Encryption
(e.g. PGP, PKZipAES)
N
4.0
Is all private data in the
solution protected?
Private Data Remains that requires additional protection solution(s) Continue Looping through until all data protected --- N
End
Y
1.3.2.1
Is the Private Data broadly
accessible to most
authorized users
Push Cryptography
out of Application
into infrastructure
stack
( file/volume/disk )
Y
1.3.2.2
Is Database-Level
Encryption
Available/supported by
Db Vendor?
1.3.2.3
Encrypt using
Database-Level
Encryption
(e.g. Oracle TDE,
MSSQL TDE)
Y
1.3.2.4
Is Volume Level
Encryption
Available?
N
1.3.2.5
Encrypt using
Volume-Level
Encryption
(e.g. Vormetric, efs,
Bitlocker)
Y
1.3.2.6
Is Hardware-based
Storage
Encryption
Available?
N
1.3.2.7
Encrypt using
Hardware-based
Storage Encryption
(e.g. encrypted hard
drives, SAN crypto)
Y
1.3.3.2
Is Integrated Database
Encryption Available (e.g.
Column-level encryption)
N
1.4
Application-based
Crypto
N
Y
1.3.2.11
Does the Private Data
comprise a large part of
the total database?
N
Y
1.3.2.12
Does the Private Data have
a high rate of update or
very-high rate of read?
Y
N
1.3.3.1
Must the Private Data be a
keyed or indexed field in a
database?
N
N
Y
1.3.3.3
Encrypt using Integrated
Database Encryption
(e.g. Column-Level
Encryption)
1.4.3
Encrypt using Application
based API (e.g. MS-CAPI)
1.4.1
Do all Application
Points support a SOA
model?
N
1.4.2
Is an API
available for the
Application?
Y
1.4.5
Custom Cryptography
1.4.4
Use/Create Encryption
Web Services/SOA
Model
1.3.2.2a
Is this a Batch Process? Y
N
Y
N
Decision Tree: Encryption of Data at RestDecision Tree: Encryption of Data at Rest Dan Houser 4/2/2013 ver3.2Dan Houser 4/2/2013 ver3.2
Cardinal Public – Internal Use OnlyCardinal Public – Internal Use Only
Preferences:
Eliminate
Reduce
Redact/ Scrub
Anonymize/De-Identify
Tokenize
Platform Encryption
SOA-based Encryption
API Encryption
Custom Encryption
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Risk-based model to drive protection
Method Pros Cons
Eliminate
Copies
Permits data to be
deleted
Requires app
change
Scrub Data Minimizes private
data propagation
May constrain
business
Anonymize Protects privacy
while permitting
analytics
Impact to the
business
Tokenize Protects data without
schema change
Impact to the
business
Encrypt Most useful format Likely code
changes
18
Risk
Disruption
Has to map to realities of BigData analytics
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Anonymize / De-Identify Segregation Model
Private Data without Identity is no longer Private*
Three Tier Segregation Model:
1. Private Identity Data – Identity data which is itself
private – e.g. Employee ID, National Identifier
2. Identity Data – Data to identify the subject of the
associated data – e.g. Name, Address
3. Private Attributes – Data only sensitive when
associated with an identity – e.g. blood type
*Except in rare cases where the Law decides it’s private without Identity.
19
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Tokenization Must Support Analytics
Transform private data into non-sensitive data
 Complete Tokenization
 Context Tokenization
20
Address Tokenized Address
1313 Mockingbird Ln 1234 Flurhtyto
1700 Pennsylvania Ave 810 Trivnignh
1411 N. Park Ave 0909 Sefpoijefiu
Address Tokenized Address
1313 Mockingbird Ln 1313 Flurhtyto
1700 Pennsylvania Ave 1700 Trivnignh
1411 N. Park Ave 1411 Sefpoijefiu
Note: Example only. Address is one of the 18 protected HIPAA ePHI identifiers.
For discussion purposes only.
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Encryption Must Support Analytics
Transform private data into non-sensitive data
 Complete Encryption
 Context Encryption
21
Address Tokenized Address
1313 Mockingbird Ln A76a39daf6e83363372d326
1700 Pennsylvania Ave 9eeb8dc55d37388b18c12b4
1411 N. Park Ave 0f2ef91d336d38b4db3be54
Address Tokenized Address
1313 Mockingbird Ln 1313 1fe3f0301b6ef39343c
1700 Pennsylvania Ave 1700 4bf1ded189e438ce11f
1411 N. Park Ave 1411 6b39cba99a3d8c47921
Note: Example only. Address is one of the 18 protected HIPAA ePHI
identifiers. For discussion purposes only.
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Hadoop Data Protection
Tokenization Architecture
22
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Multi-tenant regions:
Hadoop Data Protection
Tokenization Architecture
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Lessons Learned: Information Classification
• Governance not able to keep pace with projects
– Analytics teams experiencing very rapid build-out
– Staffing model creates challenge
– Had to develop new checkpoints to match project pacing
• Gaps in knowledge based on context
– Name is always, obviously, privacy data
– When is IP address? Ship-to address? Payer Address?
• Education & Awareness Key
– HIPAA awareness training, particularly 18 ePHI fields
– Privacy awareness training
– Information Classification training
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Lessons Learned: Data Governance
• Strategy relied on zero confidential data, but that didn’t
always map to reality.
• BigData wants all the data, Data Security would prefer
none is duplicated or copied, creating opposing goals
• Phased approach to data protection successful
• Cannot slow down the business and velocity of big
data analytics to revamp data governance, so data
governance velocity must match business imperatives
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Application
26
• Ensure the right players are at the table: Legal, Privacy,
Compliance, Analytics team, Data Architect, Business Data
Owner, Data Steward, Security Architect, etc.
• Consider nimble approaches to governing and managing
the security models in BigData
• Don’t be afraid to challenge the status quo and take risks to
develop innovative solutions
• Sometimes you can do more with less, without sacrificing
security
• Get engaged with security, legal and architects day one
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Q&A
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
Discuss…
• What is your top concern?
• What has been your experience?
• How are you addressing the access model in big data?
• Has a data stratification approach worked, or are you
relying on isolated environments?
• How has cloud integration effected ability to support
Big Data Security?
© Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and
ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.
29
Dan.houser@cardinalhealth.com
Dan.houser@isc2.org
@SecWonk
Portions © Copyright 2013, Cardinal Health, Inc. or one of its subsidiaries. All rights reserved.

More Related Content

What's hot

AIOUG : OTNYathra - Troubleshooting and Diagnosing Oracle Database 12.2 and O...
AIOUG : OTNYathra - Troubleshooting and Diagnosing Oracle Database 12.2 and O...AIOUG : OTNYathra - Troubleshooting and Diagnosing Oracle Database 12.2 and O...
AIOUG : OTNYathra - Troubleshooting and Diagnosing Oracle Database 12.2 and O...Sandesh Rao
 
IDERA Live | Maintaining Data Governance During Rapidly Changing Conditions
IDERA Live | Maintaining Data Governance During Rapidly Changing ConditionsIDERA Live | Maintaining Data Governance During Rapidly Changing Conditions
IDERA Live | Maintaining Data Governance During Rapidly Changing ConditionsIDERA Software
 
Big Data Management System: Smart SQL Processing Across Hadoop and your Data ...
Big Data Management System: Smart SQL Processing Across Hadoop and your Data ...Big Data Management System: Smart SQL Processing Across Hadoop and your Data ...
Big Data Management System: Smart SQL Processing Across Hadoop and your Data ...DataWorks Summit
 
F&S Award and Report
F&S Award and Report F&S Award and Report
F&S Award and Report Su Ahmad
 
8 from zero to insight with real time big data
8 from zero to insight with real time big data8 from zero to insight with real time big data
8 from zero to insight with real time big dataDr. Wilfred Lin (Ph.D.)
 
Cdcr oracle exadata case study
Cdcr oracle exadata case  studyCdcr oracle exadata case  study
Cdcr oracle exadata case studyjoepanora
 
IDERA Live | Why You Need Data Warehouse Automation Now More Than Ever
IDERA Live | Why You Need Data Warehouse Automation Now More Than EverIDERA Live | Why You Need Data Warehouse Automation Now More Than Ever
IDERA Live | Why You Need Data Warehouse Automation Now More Than EverIDERA Software
 
IDERA Live | The Modern Query Optimizer
IDERA Live | The Modern Query OptimizerIDERA Live | The Modern Query Optimizer
IDERA Live | The Modern Query OptimizerIDERA Software
 
CDRC Oracle exadata final case-study
CDRC Oracle exadata final case-studyCDRC Oracle exadata final case-study
CDRC Oracle exadata final case-studyjoepanora
 
IDERA Live | Have No Fear the DBA is Here: Protecting Data Resources
IDERA Live | Have No Fear the DBA is Here: Protecting Data ResourcesIDERA Live | Have No Fear the DBA is Here: Protecting Data Resources
IDERA Live | Have No Fear the DBA is Here: Protecting Data ResourcesIDERA Software
 
Exclusive Verizon Employee Webinar: Getting More From Your CDR Data
Exclusive Verizon Employee Webinar: Getting More From Your CDR DataExclusive Verizon Employee Webinar: Getting More From Your CDR Data
Exclusive Verizon Employee Webinar: Getting More From Your CDR DataPentaho
 
VNA Technology-Evaluation Checklist
VNA Technology-Evaluation ChecklistVNA Technology-Evaluation Checklist
VNA Technology-Evaluation ChecklistCarestream
 
Meaningful Use in Radiology
Meaningful Use in RadiologyMeaningful Use in Radiology
Meaningful Use in RadiologyCarestream
 
Transform You Business with Big Data and Hortonworks
Transform You Business with Big Data and HortonworksTransform You Business with Big Data and Hortonworks
Transform You Business with Big Data and HortonworksHortonworks
 
Harnessing Hadoop Distuption: A Telco Case Study
Harnessing Hadoop Distuption: A Telco Case StudyHarnessing Hadoop Distuption: A Telco Case Study
Harnessing Hadoop Distuption: A Telco Case StudyDataWorks Summit
 
NZOUG-GroundBreakers-2018 - Troubleshooting and Diagnosing 18c RAC
NZOUG-GroundBreakers-2018 - Troubleshooting and Diagnosing 18c RACNZOUG-GroundBreakers-2018 - Troubleshooting and Diagnosing 18c RAC
NZOUG-GroundBreakers-2018 - Troubleshooting and Diagnosing 18c RACSandesh Rao
 
Using FHIR for Interoperability
Using FHIR for InteroperabilityUsing FHIR for Interoperability
Using FHIR for InteroperabilityIatric Systems
 
Introduction of BJU-BMR-RG and use case study of Applying openEHR archetypes ...
Introduction of BJU-BMR-RG and use case study of Applying openEHR archetypes ...Introduction of BJU-BMR-RG and use case study of Applying openEHR archetypes ...
Introduction of BJU-BMR-RG and use case study of Applying openEHR archetypes ...openEHR-Japan
 
Big Data Integration Webinar: Getting Started With Hadoop Big Data
Big Data Integration Webinar: Getting Started With Hadoop Big DataBig Data Integration Webinar: Getting Started With Hadoop Big Data
Big Data Integration Webinar: Getting Started With Hadoop Big DataPentaho
 

What's hot (19)

AIOUG : OTNYathra - Troubleshooting and Diagnosing Oracle Database 12.2 and O...
AIOUG : OTNYathra - Troubleshooting and Diagnosing Oracle Database 12.2 and O...AIOUG : OTNYathra - Troubleshooting and Diagnosing Oracle Database 12.2 and O...
AIOUG : OTNYathra - Troubleshooting and Diagnosing Oracle Database 12.2 and O...
 
IDERA Live | Maintaining Data Governance During Rapidly Changing Conditions
IDERA Live | Maintaining Data Governance During Rapidly Changing ConditionsIDERA Live | Maintaining Data Governance During Rapidly Changing Conditions
IDERA Live | Maintaining Data Governance During Rapidly Changing Conditions
 
Big Data Management System: Smart SQL Processing Across Hadoop and your Data ...
Big Data Management System: Smart SQL Processing Across Hadoop and your Data ...Big Data Management System: Smart SQL Processing Across Hadoop and your Data ...
Big Data Management System: Smart SQL Processing Across Hadoop and your Data ...
 
F&S Award and Report
F&S Award and Report F&S Award and Report
F&S Award and Report
 
8 from zero to insight with real time big data
8 from zero to insight with real time big data8 from zero to insight with real time big data
8 from zero to insight with real time big data
 
Cdcr oracle exadata case study
Cdcr oracle exadata case  studyCdcr oracle exadata case  study
Cdcr oracle exadata case study
 
IDERA Live | Why You Need Data Warehouse Automation Now More Than Ever
IDERA Live | Why You Need Data Warehouse Automation Now More Than EverIDERA Live | Why You Need Data Warehouse Automation Now More Than Ever
IDERA Live | Why You Need Data Warehouse Automation Now More Than Ever
 
IDERA Live | The Modern Query Optimizer
IDERA Live | The Modern Query OptimizerIDERA Live | The Modern Query Optimizer
IDERA Live | The Modern Query Optimizer
 
CDRC Oracle exadata final case-study
CDRC Oracle exadata final case-studyCDRC Oracle exadata final case-study
CDRC Oracle exadata final case-study
 
IDERA Live | Have No Fear the DBA is Here: Protecting Data Resources
IDERA Live | Have No Fear the DBA is Here: Protecting Data ResourcesIDERA Live | Have No Fear the DBA is Here: Protecting Data Resources
IDERA Live | Have No Fear the DBA is Here: Protecting Data Resources
 
Exclusive Verizon Employee Webinar: Getting More From Your CDR Data
Exclusive Verizon Employee Webinar: Getting More From Your CDR DataExclusive Verizon Employee Webinar: Getting More From Your CDR Data
Exclusive Verizon Employee Webinar: Getting More From Your CDR Data
 
VNA Technology-Evaluation Checklist
VNA Technology-Evaluation ChecklistVNA Technology-Evaluation Checklist
VNA Technology-Evaluation Checklist
 
Meaningful Use in Radiology
Meaningful Use in RadiologyMeaningful Use in Radiology
Meaningful Use in Radiology
 
Transform You Business with Big Data and Hortonworks
Transform You Business with Big Data and HortonworksTransform You Business with Big Data and Hortonworks
Transform You Business with Big Data and Hortonworks
 
Harnessing Hadoop Distuption: A Telco Case Study
Harnessing Hadoop Distuption: A Telco Case StudyHarnessing Hadoop Distuption: A Telco Case Study
Harnessing Hadoop Distuption: A Telco Case Study
 
NZOUG-GroundBreakers-2018 - Troubleshooting and Diagnosing 18c RAC
NZOUG-GroundBreakers-2018 - Troubleshooting and Diagnosing 18c RACNZOUG-GroundBreakers-2018 - Troubleshooting and Diagnosing 18c RAC
NZOUG-GroundBreakers-2018 - Troubleshooting and Diagnosing 18c RAC
 
Using FHIR for Interoperability
Using FHIR for InteroperabilityUsing FHIR for Interoperability
Using FHIR for Interoperability
 
Introduction of BJU-BMR-RG and use case study of Applying openEHR archetypes ...
Introduction of BJU-BMR-RG and use case study of Applying openEHR archetypes ...Introduction of BJU-BMR-RG and use case study of Applying openEHR archetypes ...
Introduction of BJU-BMR-RG and use case study of Applying openEHR archetypes ...
 
Big Data Integration Webinar: Getting Started With Hadoop Big Data
Big Data Integration Webinar: Getting Started With Hadoop Big DataBig Data Integration Webinar: Getting Started With Hadoop Big Data
Big Data Integration Webinar: Getting Started With Hadoop Big Data
 

Similar to Case Study: Securing & Tokenizing Big Data

A Journey towards Self-Service Analytics
A Journey towards Self-Service AnalyticsA Journey towards Self-Service Analytics
A Journey towards Self-Service AnalyticsPatrick Deglon
 
Strategic imperative the enterprise data model
Strategic imperative the enterprise data modelStrategic imperative the enterprise data model
Strategic imperative the enterprise data modelDATAVERSITY
 
Data Done Right: Ensuring Information Integrity
Data Done Right: Ensuring Information IntegrityData Done Right: Ensuring Information Integrity
Data Done Right: Ensuring Information IntegritySharala Axryd
 
Oracle Big Data Governance Webcast Charts
Oracle Big Data Governance Webcast ChartsOracle Big Data Governance Webcast Charts
Oracle Big Data Governance Webcast ChartsJeffrey T. Pollock
 
Innovation to Commercialization Oracle and KPIT
Innovation to Commercialization Oracle and KPITInnovation to Commercialization Oracle and KPIT
Innovation to Commercialization Oracle and KPITRupertFallows
 
Business Value Metrics for Data Governance
Business Value Metrics for Data GovernanceBusiness Value Metrics for Data Governance
Business Value Metrics for Data GovernanceDATAVERSITY
 
Tdwi austin simplifying big data delivery to drive new insights final
Tdwi austin   simplifying big data delivery to drive new insights finalTdwi austin   simplifying big data delivery to drive new insights final
Tdwi austin simplifying big data delivery to drive new insights finalSal Marcus
 
Data Architecture - The Foundation for Enterprise Architecture and Governance
Data Architecture - The Foundation for Enterprise Architecture and GovernanceData Architecture - The Foundation for Enterprise Architecture and Governance
Data Architecture - The Foundation for Enterprise Architecture and GovernanceDATAVERSITY
 
IDERA Live | Business Value Metrics for Data Governance
IDERA Live | Business Value Metrics for Data GovernanceIDERA Live | Business Value Metrics for Data Governance
IDERA Live | Business Value Metrics for Data GovernanceIDERA Software
 
Extending BI with Big Data Analytics
Extending BI with Big Data AnalyticsExtending BI with Big Data Analytics
Extending BI with Big Data AnalyticsDatameer
 
Fast Data Overview for Data Science Maryland Meetup
Fast Data Overview for Data Science Maryland MeetupFast Data Overview for Data Science Maryland Meetup
Fast Data Overview for Data Science Maryland MeetupC. Scyphers
 
Extreme Analytics - What's New With Oracle Exalytics X3-4 & T5-8?
Extreme Analytics - What's New With Oracle Exalytics X3-4 & T5-8?Extreme Analytics - What's New With Oracle Exalytics X3-4 & T5-8?
Extreme Analytics - What's New With Oracle Exalytics X3-4 & T5-8?KPI Partners
 
IDERA Live | Decode your Organization's Data DNA
IDERA Live | Decode your Organization's Data DNAIDERA Live | Decode your Organization's Data DNA
IDERA Live | Decode your Organization's Data DNAIDERA Software
 
Case Study: Cardinal Health Experiences “Black Friday” Every Day
Case Study: Cardinal Health Experiences “Black Friday” Every DayCase Study: Cardinal Health Experiences “Black Friday” Every Day
Case Study: Cardinal Health Experiences “Black Friday” Every DayCA Technologies
 
6 enriching your data warehouse with big data and hadoop
6 enriching your data warehouse with big data and hadoop6 enriching your data warehouse with big data and hadoop
6 enriching your data warehouse with big data and hadoopDr. Wilfred Lin (Ph.D.)
 
Operationalizing Data Analytics
Operationalizing Data AnalyticsOperationalizing Data Analytics
Operationalizing Data AnalyticsVMware Tanzu
 
Solving the Data Management Challenge for Healthcare
Solving the Data Management Challenge for HealthcareSolving the Data Management Challenge for Healthcare
Solving the Data Management Challenge for HealthcareDelphix
 
What you need to know before migrating to SAP Hana
What you need to know before migrating to SAP HanaWhat you need to know before migrating to SAP Hana
What you need to know before migrating to SAP HanaDataVard
 
3 reach new heights of operational effectiveness while simplifying it with or...
3 reach new heights of operational effectiveness while simplifying it with or...3 reach new heights of operational effectiveness while simplifying it with or...
3 reach new heights of operational effectiveness while simplifying it with or...Dr. Wilfred Lin (Ph.D.)
 

Similar to Case Study: Securing & Tokenizing Big Data (20)

A Journey towards Self-Service Analytics
A Journey towards Self-Service AnalyticsA Journey towards Self-Service Analytics
A Journey towards Self-Service Analytics
 
Strategic imperative the enterprise data model
Strategic imperative the enterprise data modelStrategic imperative the enterprise data model
Strategic imperative the enterprise data model
 
Data Done Right: Ensuring Information Integrity
Data Done Right: Ensuring Information IntegrityData Done Right: Ensuring Information Integrity
Data Done Right: Ensuring Information Integrity
 
Oracle Big Data Governance Webcast Charts
Oracle Big Data Governance Webcast ChartsOracle Big Data Governance Webcast Charts
Oracle Big Data Governance Webcast Charts
 
Apouc 2014-business-analytics-and-big-data
Apouc 2014-business-analytics-and-big-dataApouc 2014-business-analytics-and-big-data
Apouc 2014-business-analytics-and-big-data
 
Innovation to Commercialization Oracle and KPIT
Innovation to Commercialization Oracle and KPITInnovation to Commercialization Oracle and KPIT
Innovation to Commercialization Oracle and KPIT
 
Business Value Metrics for Data Governance
Business Value Metrics for Data GovernanceBusiness Value Metrics for Data Governance
Business Value Metrics for Data Governance
 
Tdwi austin simplifying big data delivery to drive new insights final
Tdwi austin   simplifying big data delivery to drive new insights finalTdwi austin   simplifying big data delivery to drive new insights final
Tdwi austin simplifying big data delivery to drive new insights final
 
Data Architecture - The Foundation for Enterprise Architecture and Governance
Data Architecture - The Foundation for Enterprise Architecture and GovernanceData Architecture - The Foundation for Enterprise Architecture and Governance
Data Architecture - The Foundation for Enterprise Architecture and Governance
 
IDERA Live | Business Value Metrics for Data Governance
IDERA Live | Business Value Metrics for Data GovernanceIDERA Live | Business Value Metrics for Data Governance
IDERA Live | Business Value Metrics for Data Governance
 
Extending BI with Big Data Analytics
Extending BI with Big Data AnalyticsExtending BI with Big Data Analytics
Extending BI with Big Data Analytics
 
Fast Data Overview for Data Science Maryland Meetup
Fast Data Overview for Data Science Maryland MeetupFast Data Overview for Data Science Maryland Meetup
Fast Data Overview for Data Science Maryland Meetup
 
Extreme Analytics - What's New With Oracle Exalytics X3-4 & T5-8?
Extreme Analytics - What's New With Oracle Exalytics X3-4 & T5-8?Extreme Analytics - What's New With Oracle Exalytics X3-4 & T5-8?
Extreme Analytics - What's New With Oracle Exalytics X3-4 & T5-8?
 
IDERA Live | Decode your Organization's Data DNA
IDERA Live | Decode your Organization's Data DNAIDERA Live | Decode your Organization's Data DNA
IDERA Live | Decode your Organization's Data DNA
 
Case Study: Cardinal Health Experiences “Black Friday” Every Day
Case Study: Cardinal Health Experiences “Black Friday” Every DayCase Study: Cardinal Health Experiences “Black Friday” Every Day
Case Study: Cardinal Health Experiences “Black Friday” Every Day
 
6 enriching your data warehouse with big data and hadoop
6 enriching your data warehouse with big data and hadoop6 enriching your data warehouse with big data and hadoop
6 enriching your data warehouse with big data and hadoop
 
Operationalizing Data Analytics
Operationalizing Data AnalyticsOperationalizing Data Analytics
Operationalizing Data Analytics
 
Solving the Data Management Challenge for Healthcare
Solving the Data Management Challenge for HealthcareSolving the Data Management Challenge for Healthcare
Solving the Data Management Challenge for Healthcare
 
What you need to know before migrating to SAP Hana
What you need to know before migrating to SAP HanaWhat you need to know before migrating to SAP Hana
What you need to know before migrating to SAP Hana
 
3 reach new heights of operational effectiveness while simplifying it with or...
3 reach new heights of operational effectiveness while simplifying it with or...3 reach new heights of operational effectiveness while simplifying it with or...
3 reach new heights of operational effectiveness while simplifying it with or...
 

More from Dan Houser

Hacking Bourbon
Hacking BourbonHacking Bourbon
Hacking BourbonDan Houser
 
2013 (ISC)² Congress: This Curious Thing Called Ethics
2013 (ISC)² Congress: This Curious Thing Called Ethics2013 (ISC)² Congress: This Curious Thing Called Ethics
2013 (ISC)² Congress: This Curious Thing Called EthicsDan Houser
 
RSA2008: What Vendors Won’t Tell You About Federated Identity
RSA2008: What Vendors Won’t Tell You About Federated IdentityRSA2008: What Vendors Won’t Tell You About Federated Identity
RSA2008: What Vendors Won’t Tell You About Federated IdentityDan Houser
 
The Challenges & Risks of New Technology: Privacy Law & Policy
The Challenges & Risks of New Technology: Privacy Law & PolicyThe Challenges & Risks of New Technology: Privacy Law & Policy
The Challenges & Risks of New Technology: Privacy Law & PolicyDan Houser
 
Perimeter Defense in a World Without Walls
Perimeter Defense in a World Without WallsPerimeter Defense in a World Without Walls
Perimeter Defense in a World Without WallsDan Houser
 
Risk Based Planning for Mission Continuity
Risk Based Planning for Mission ContinuityRisk Based Planning for Mission Continuity
Risk Based Planning for Mission ContinuityDan Houser
 
Security Capability Model - InfoSec Forum VIII
Security Capability Model - InfoSec Forum VIIISecurity Capability Model - InfoSec Forum VIII
Security Capability Model - InfoSec Forum VIIIDan Houser
 
Certifications and Career Development for Security Professionals
Certifications and Career Development for Security ProfessionalsCertifications and Career Development for Security Professionals
Certifications and Career Development for Security ProfessionalsDan Houser
 
Advanced IAM - Surviving the IAM Audit
Advanced IAM - Surviving the IAM AuditAdvanced IAM - Surviving the IAM Audit
Advanced IAM - Surviving the IAM AuditDan Houser
 
Debunking Information Security myths
Debunking Information Security mythsDebunking Information Security myths
Debunking Information Security mythsDan Houser
 
Hacking a Major Security Conference
Hacking a Major Security ConferenceHacking a Major Security Conference
Hacking a Major Security ConferenceDan Houser
 
Building & Running A Successful Identity Program
Building & Running A Successful Identity ProgramBuilding & Running A Successful Identity Program
Building & Running A Successful Identity ProgramDan Houser
 
Crypto in the Real World: or How to Scare an IT Auditor
Crypto in the Real World: or How to Scare an IT AuditorCrypto in the Real World: or How to Scare an IT Auditor
Crypto in the Real World: or How to Scare an IT AuditorDan Houser
 

More from Dan Houser (13)

Hacking Bourbon
Hacking BourbonHacking Bourbon
Hacking Bourbon
 
2013 (ISC)² Congress: This Curious Thing Called Ethics
2013 (ISC)² Congress: This Curious Thing Called Ethics2013 (ISC)² Congress: This Curious Thing Called Ethics
2013 (ISC)² Congress: This Curious Thing Called Ethics
 
RSA2008: What Vendors Won’t Tell You About Federated Identity
RSA2008: What Vendors Won’t Tell You About Federated IdentityRSA2008: What Vendors Won’t Tell You About Federated Identity
RSA2008: What Vendors Won’t Tell You About Federated Identity
 
The Challenges & Risks of New Technology: Privacy Law & Policy
The Challenges & Risks of New Technology: Privacy Law & PolicyThe Challenges & Risks of New Technology: Privacy Law & Policy
The Challenges & Risks of New Technology: Privacy Law & Policy
 
Perimeter Defense in a World Without Walls
Perimeter Defense in a World Without WallsPerimeter Defense in a World Without Walls
Perimeter Defense in a World Without Walls
 
Risk Based Planning for Mission Continuity
Risk Based Planning for Mission ContinuityRisk Based Planning for Mission Continuity
Risk Based Planning for Mission Continuity
 
Security Capability Model - InfoSec Forum VIII
Security Capability Model - InfoSec Forum VIIISecurity Capability Model - InfoSec Forum VIII
Security Capability Model - InfoSec Forum VIII
 
Certifications and Career Development for Security Professionals
Certifications and Career Development for Security ProfessionalsCertifications and Career Development for Security Professionals
Certifications and Career Development for Security Professionals
 
Advanced IAM - Surviving the IAM Audit
Advanced IAM - Surviving the IAM AuditAdvanced IAM - Surviving the IAM Audit
Advanced IAM - Surviving the IAM Audit
 
Debunking Information Security myths
Debunking Information Security mythsDebunking Information Security myths
Debunking Information Security myths
 
Hacking a Major Security Conference
Hacking a Major Security ConferenceHacking a Major Security Conference
Hacking a Major Security Conference
 
Building & Running A Successful Identity Program
Building & Running A Successful Identity ProgramBuilding & Running A Successful Identity Program
Building & Running A Successful Identity Program
 
Crypto in the Real World: or How to Scare an IT Auditor
Crypto in the Real World: or How to Scare an IT AuditorCrypto in the Real World: or How to Scare an IT Auditor
Crypto in the Real World: or How to Scare an IT Auditor
 

Recently uploaded

INTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTDINTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTDRafezzaman
 
PKS-TGC-1084-630 - Stage 1 Proposal.pptx
PKS-TGC-1084-630 - Stage 1 Proposal.pptxPKS-TGC-1084-630 - Stage 1 Proposal.pptx
PKS-TGC-1084-630 - Stage 1 Proposal.pptxPramod Kumar Srivastava
 
20240419 - Measurecamp Amsterdam - SAM.pdf
20240419 - Measurecamp Amsterdam - SAM.pdf20240419 - Measurecamp Amsterdam - SAM.pdf
20240419 - Measurecamp Amsterdam - SAM.pdfHuman37
 
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一F La
 
原版1:1定制南十字星大学毕业证(SCU毕业证)#文凭成绩单#真实留信学历认证永久存档
原版1:1定制南十字星大学毕业证(SCU毕业证)#文凭成绩单#真实留信学历认证永久存档原版1:1定制南十字星大学毕业证(SCU毕业证)#文凭成绩单#真实留信学历认证永久存档
原版1:1定制南十字星大学毕业证(SCU毕业证)#文凭成绩单#真实留信学历认证永久存档208367051
 
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...Sapana Sha
 
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024thyngster
 
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一F sss
 
Call Girls In Dwarka 9654467111 Escorts Service
Call Girls In Dwarka 9654467111 Escorts ServiceCall Girls In Dwarka 9654467111 Escorts Service
Call Girls In Dwarka 9654467111 Escorts ServiceSapana Sha
 
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Generative AI for Social Good at Open Data Science East 2024
Generative AI for Social Good at Open Data Science East 2024Generative AI for Social Good at Open Data Science East 2024
Generative AI for Social Good at Open Data Science East 2024Colleen Farrelly
 
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdfKantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdfSocial Samosa
 
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)jennyeacort
 
RS 9000 Call In girls Dwarka Mor (DELHI)⇛9711147426🔝Delhi
RS 9000 Call In girls Dwarka Mor (DELHI)⇛9711147426🔝DelhiRS 9000 Call In girls Dwarka Mor (DELHI)⇛9711147426🔝Delhi
RS 9000 Call In girls Dwarka Mor (DELHI)⇛9711147426🔝Delhijennyeacort
 
Predicting Salary Using Data Science: A Comprehensive Analysis.pdf
Predicting Salary Using Data Science: A Comprehensive Analysis.pdfPredicting Salary Using Data Science: A Comprehensive Analysis.pdf
Predicting Salary Using Data Science: A Comprehensive Analysis.pdfBoston Institute of Analytics
 
GA4 Without Cookies [Measure Camp AMS]
GA4 Without Cookies [Measure Camp AMS]GA4 Without Cookies [Measure Camp AMS]
GA4 Without Cookies [Measure Camp AMS]📊 Markus Baersch
 
科罗拉多大学波尔得分校毕业证学位证成绩单-可办理
科罗拉多大学波尔得分校毕业证学位证成绩单-可办理科罗拉多大学波尔得分校毕业证学位证成绩单-可办理
科罗拉多大学波尔得分校毕业证学位证成绩单-可办理e4aez8ss
 
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptx
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptxAmazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptx
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptxAbdelrhman abooda
 
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...dajasot375
 

Recently uploaded (20)

INTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTDINTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTD
 
PKS-TGC-1084-630 - Stage 1 Proposal.pptx
PKS-TGC-1084-630 - Stage 1 Proposal.pptxPKS-TGC-1084-630 - Stage 1 Proposal.pptx
PKS-TGC-1084-630 - Stage 1 Proposal.pptx
 
20240419 - Measurecamp Amsterdam - SAM.pdf
20240419 - Measurecamp Amsterdam - SAM.pdf20240419 - Measurecamp Amsterdam - SAM.pdf
20240419 - Measurecamp Amsterdam - SAM.pdf
 
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一
办理(Vancouver毕业证书)加拿大温哥华岛大学毕业证成绩单原版一比一
 
原版1:1定制南十字星大学毕业证(SCU毕业证)#文凭成绩单#真实留信学历认证永久存档
原版1:1定制南十字星大学毕业证(SCU毕业证)#文凭成绩单#真实留信学历认证永久存档原版1:1定制南十字星大学毕业证(SCU毕业证)#文凭成绩单#真实留信学历认证永久存档
原版1:1定制南十字星大学毕业证(SCU毕业证)#文凭成绩单#真实留信学历认证永久存档
 
Call Girls in Saket 99530🔝 56974 Escort Service
Call Girls in Saket 99530🔝 56974 Escort ServiceCall Girls in Saket 99530🔝 56974 Escort Service
Call Girls in Saket 99530🔝 56974 Escort Service
 
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...
 
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024
Consent & Privacy Signals on Google *Pixels* - MeasureCamp Amsterdam 2024
 
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
 
Call Girls In Dwarka 9654467111 Escorts Service
Call Girls In Dwarka 9654467111 Escorts ServiceCall Girls In Dwarka 9654467111 Escorts Service
Call Girls In Dwarka 9654467111 Escorts Service
 
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
 
Generative AI for Social Good at Open Data Science East 2024
Generative AI for Social Good at Open Data Science East 2024Generative AI for Social Good at Open Data Science East 2024
Generative AI for Social Good at Open Data Science East 2024
 
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdfKantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
 
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)
 
RS 9000 Call In girls Dwarka Mor (DELHI)⇛9711147426🔝Delhi
RS 9000 Call In girls Dwarka Mor (DELHI)⇛9711147426🔝DelhiRS 9000 Call In girls Dwarka Mor (DELHI)⇛9711147426🔝Delhi
RS 9000 Call In girls Dwarka Mor (DELHI)⇛9711147426🔝Delhi
 
Predicting Salary Using Data Science: A Comprehensive Analysis.pdf
Predicting Salary Using Data Science: A Comprehensive Analysis.pdfPredicting Salary Using Data Science: A Comprehensive Analysis.pdf
Predicting Salary Using Data Science: A Comprehensive Analysis.pdf
 
GA4 Without Cookies [Measure Camp AMS]
GA4 Without Cookies [Measure Camp AMS]GA4 Without Cookies [Measure Camp AMS]
GA4 Without Cookies [Measure Camp AMS]
 
科罗拉多大学波尔得分校毕业证学位证成绩单-可办理
科罗拉多大学波尔得分校毕业证学位证成绩单-可办理科罗拉多大学波尔得分校毕业证学位证成绩单-可办理
科罗拉多大学波尔得分校毕业证学位证成绩单-可办理
 
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptx
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptxAmazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptx
Amazon TQM (2) Amazon TQM (2)Amazon TQM (2).pptx
 
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...
Indian Call Girls in Abu Dhabi O5286O24O8 Call Girls in Abu Dhabi By Independ...
 

Case Study: Securing & Tokenizing Big Data

  • 1. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Case Study: Securing & Tokenizing Big Data Dan Houser, CISSP-ISSAP-ISSMP CSSLP HCISPP @SecWonk Principal Security & Identity Architect 24-April-2014
  • 2. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. AGENDA Drivers for Big Data Cardboard Bicycles Challenging the Status Quo Cardinal Big Data Security Model Access Model Lessons Learned 2
  • 3. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Cardinal Health 30,000 plus employees with direct operations in 10 countries 60,000 sites delivered to daily 3 *An estimate of the pro forma revenue for fiscal 2012 in accordance with generally accepted accounting principles with adjustments expected to reflect each company as a stand-alone entity. The estimate is based on assumptions that management currently believes are reasonable, but actual revenue may vary materially from the estimate. Leading provider of products and services across the healthcare supply chain with an extensive footprint across multiple channels $108B FY12 pro forma revenue* #21 on Fortune 500 list 86% of hospitals in the U.S. use our products and services
  • 4. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Essential purpose We are more than 30,000 people applying our deep understanding of healthcare to deliver inventive and meaningful solutions that help improve the cost-effectiveness and quality of healthcare so our customers can focus on patients. 4
  • 5. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Essential role We are the business behind healthcare 5
  • 6. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. 6 Hadoop Vision Background Cardinal Health is increasingly emphasizing the importance of advanced analytics due to the financial benefits, competitive advantage and organizational effectiveness enabled by the growing # of successes from our analytics initiatives. Business Needs To further advance Cardinal Health into a transformed company with analytics prescribed actions*, increased ROI, reduced complexity, and improve our overall efficiency, we need to optimize existing assets, accelerate adoption of learning from existing success stories (and failures) and enable an affordable, scalable and agile platform to meet business need of increased decision velocity as well as trusted data attainability & usability. * Transformed Company is defined in MIT/IBM Sloan 2012 research on Analytics as companies with rigorously data driven decision making culture and with daily critical data insights and analytics prescribed actions
  • 7. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. 7 Hadoop Business Opportunity • Provide the most cost effective capability to quickly react to the changing business needs • Leverage machine learning, pattern-recognition capabilities across disparate datasets for deep data analytics • Support Cardinal Health’s Master Data Management plan • Securely manage analytical data required for our clinical analytics applications (including HIPAA data)
  • 8. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. 8 High-level Hadoop at Cardinal
  • 9. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Cardboard Bicycles Our Hadoop architecture is radical, and based on the premise of the Cardboard Bicycle Innovative Consumable IT Low-cost Zero-touch model Image courtesy: Cardboard Technologies http://goo.gl/ztWvR
  • 10. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Internal use only Criteria Conventional Hadoop Fault Domain Server (Toyota Camry) Rack of servers (Paper Bicycle) Server repair Hours Days Server Cost 19% Storage Cost 3% Cost/Analytical GB 1% of SAS 4% of Teradata Performance Server Across Grid Management Server Server Type Admins/Server 100/1 1000/1 Uniqueness Every server unique All servers alike Lifecycle 3 years Till it dies Troubleshooting By Server (App) As a whole Ability to Evolve Quarterly Daily (if needed) Operating System Locally Installed Network Bootable In Memory Unique Ideas
  • 11. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. 11 Risks & Mitigating Strategies • Rapidly Evolving Open Source Project • Open model by default • Massive data repository • Inference can lead to de-anonymization • Data corruption • Delayed adoption of new features until vetted • Data access controlled by data owners group • Adhoc access limited • Not allowing any private, HIPAA, or other controlled data into the environment without encryption/masking • Creating replica of production onto a backup cluster Risk Mitigation
  • 12. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. 12 Hadoop Architecture
  • 13. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Access Nodes 13 Role-based Access Model • Segmented access control to access/ control/ data nodes • Active Directory groups • Secure groups for data segmentation where sensitive • Vintella Authentication using Kerberos • Access Nodes can talk to Control Nodes, Control Nodes can talk to Data Nodes, User restricted to Access Layer Datameer Admin Data Nodes Users Power Users AD MySQL Sqoop Hive Flume Control Nodes Developers Data Owners
  • 14. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. 14 Security Model • EA and Hadoop project team have implemented world-class Hadoop security model • Host-based firewalls on control & data nodes – Locked down using iptables – Block connections from unauthorized hosts • Gold-image boot for data nodes – No persistent OS / config data - continuous fresh, secure image – Ease of security patching
  • 15. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. 15 Security Model • Segregated VLAN on dedicated network switches • Supported open source via Hortonworks • Backup environment for data integrity (not DR) • Segregated Prod, Tek, Integration, Backup environments • Transaction, security and event logging • Host-based file integrity monitoring
  • 16. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. 16 Security Challenges • Information Classification continues to be difficult for IT and business teams, particularly when otherwise innocuous data is made sensitive in context. • Anonymization patterns emergent – differing patterns applied in source repositories • No enterprise-wide cryptographic solution providing format-preserving or context encryption • Detection & Prevention of de-anonymization is a problem for the industry, and also for us • Data Governance within Hadoop team going 100mph
  • 17. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health.17 Decision Tree Start 1.0 Input in Cleartext? Y 1.1 Can it be Redacted? Y 1.1.1 Redact/scrub the data SSN:111-22-3333 Ê xxx-xx-3333 1.2 Can it be tokenized? N Y 1.2.1 Tokenize the Data SSN:123-45-6789 Ê 987-31-4929 2.0 Output in Cleartext? 1.3 Must encrypt N N 3.0 Does data always remain encrypted? N Y Y 3.1 No cryptography needed for data at rest 3.2 Need to decrypt and encrypt within solution Go to 1.1 N 1.3.1 Is Data shared Externally? Y 1.3.1.1 Use File / Folder Level Encryption (e.g. PGP, PKZipAES) N 4.0 Is all private data in the solution protected? Private Data Remains that requires additional protection solution(s) Continue Looping through until all data protected --- N End Y 1.3.2.1 Is the Private Data broadly accessible to most authorized users Push Cryptography out of Application into infrastructure stack ( file/volume/disk ) Y 1.3.2.2 Is Database-Level Encryption Available/supported by Db Vendor? 1.3.2.3 Encrypt using Database-Level Encryption (e.g. Oracle TDE, MSSQL TDE) Y 1.3.2.4 Is Volume Level Encryption Available? N 1.3.2.5 Encrypt using Volume-Level Encryption (e.g. Vormetric, efs, Bitlocker) Y 1.3.2.6 Is Hardware-based Storage Encryption Available? N 1.3.2.7 Encrypt using Hardware-based Storage Encryption (e.g. encrypted hard drives, SAN crypto) Y 1.3.3.2 Is Integrated Database Encryption Available (e.g. Column-level encryption) N 1.4 Application-based Crypto N Y 1.3.2.11 Does the Private Data comprise a large part of the total database? N Y 1.3.2.12 Does the Private Data have a high rate of update or very-high rate of read? Y N 1.3.3.1 Must the Private Data be a keyed or indexed field in a database? N N Y 1.3.3.3 Encrypt using Integrated Database Encryption (e.g. Column-Level Encryption) 1.4.3 Encrypt using Application based API (e.g. MS-CAPI) 1.4.1 Do all Application Points support a SOA model? N 1.4.2 Is an API available for the Application? Y 1.4.5 Custom Cryptography 1.4.4 Use/Create Encryption Web Services/SOA Model 1.3.2.2a Is this a Batch Process? Y N Y N Decision Tree: Encryption of Data at RestDecision Tree: Encryption of Data at Rest Dan Houser 4/2/2013 ver3.2Dan Houser 4/2/2013 ver3.2 Cardinal Public – Internal Use OnlyCardinal Public – Internal Use Only Preferences: Eliminate Reduce Redact/ Scrub Anonymize/De-Identify Tokenize Platform Encryption SOA-based Encryption API Encryption Custom Encryption
  • 18. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Risk-based model to drive protection Method Pros Cons Eliminate Copies Permits data to be deleted Requires app change Scrub Data Minimizes private data propagation May constrain business Anonymize Protects privacy while permitting analytics Impact to the business Tokenize Protects data without schema change Impact to the business Encrypt Most useful format Likely code changes 18 Risk Disruption Has to map to realities of BigData analytics
  • 19. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Anonymize / De-Identify Segregation Model Private Data without Identity is no longer Private* Three Tier Segregation Model: 1. Private Identity Data – Identity data which is itself private – e.g. Employee ID, National Identifier 2. Identity Data – Data to identify the subject of the associated data – e.g. Name, Address 3. Private Attributes – Data only sensitive when associated with an identity – e.g. blood type *Except in rare cases where the Law decides it’s private without Identity. 19
  • 20. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Tokenization Must Support Analytics Transform private data into non-sensitive data  Complete Tokenization  Context Tokenization 20 Address Tokenized Address 1313 Mockingbird Ln 1234 Flurhtyto 1700 Pennsylvania Ave 810 Trivnignh 1411 N. Park Ave 0909 Sefpoijefiu Address Tokenized Address 1313 Mockingbird Ln 1313 Flurhtyto 1700 Pennsylvania Ave 1700 Trivnignh 1411 N. Park Ave 1411 Sefpoijefiu Note: Example only. Address is one of the 18 protected HIPAA ePHI identifiers. For discussion purposes only.
  • 21. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Encryption Must Support Analytics Transform private data into non-sensitive data  Complete Encryption  Context Encryption 21 Address Tokenized Address 1313 Mockingbird Ln A76a39daf6e83363372d326 1700 Pennsylvania Ave 9eeb8dc55d37388b18c12b4 1411 N. Park Ave 0f2ef91d336d38b4db3be54 Address Tokenized Address 1313 Mockingbird Ln 1313 1fe3f0301b6ef39343c 1700 Pennsylvania Ave 1700 4bf1ded189e438ce11f 1411 N. Park Ave 1411 6b39cba99a3d8c47921 Note: Example only. Address is one of the 18 protected HIPAA ePHI identifiers. For discussion purposes only.
  • 22. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Hadoop Data Protection Tokenization Architecture 22
  • 23. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Multi-tenant regions: Hadoop Data Protection Tokenization Architecture
  • 24. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Lessons Learned: Information Classification • Governance not able to keep pace with projects – Analytics teams experiencing very rapid build-out – Staffing model creates challenge – Had to develop new checkpoints to match project pacing • Gaps in knowledge based on context – Name is always, obviously, privacy data – When is IP address? Ship-to address? Payer Address? • Education & Awareness Key – HIPAA awareness training, particularly 18 ePHI fields – Privacy awareness training – Information Classification training
  • 25. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Lessons Learned: Data Governance • Strategy relied on zero confidential data, but that didn’t always map to reality. • BigData wants all the data, Data Security would prefer none is duplicated or copied, creating opposing goals • Phased approach to data protection successful • Cannot slow down the business and velocity of big data analytics to revamp data governance, so data governance velocity must match business imperatives
  • 26. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Application 26 • Ensure the right players are at the table: Legal, Privacy, Compliance, Analytics team, Data Architect, Business Data Owner, Data Steward, Security Architect, etc. • Consider nimble approaches to governing and managing the security models in BigData • Don’t be afraid to challenge the status quo and take risks to develop innovative solutions • Sometimes you can do more with less, without sacrificing security • Get engaged with security, legal and architects day one
  • 27. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Q&A
  • 28. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. Discuss… • What is your top concern? • What has been your experience? • How are you addressing the access model in big data? • Has a data stratification approach worked, or are you relying on isolated environments? • How has cloud integration effected ability to support Big Data Security?
  • 29. © Copyright 2013, Cardinal Health. All rights reserved. CARDINAL HEALTH, the Cardinal Health LOGO and ESSENTIAL TO CARE are trademarks or registered trademarks of Cardinal Health. 29 Dan.houser@cardinalhealth.com Dan.houser@isc2.org @SecWonk Portions © Copyright 2013, Cardinal Health, Inc. or one of its subsidiaries. All rights reserved.

Editor's Notes

  1. Cardinal Health is a multi-billion dollar healthcare services company. Actually, we like to say we’re the business behind healthcare because we focus on making it more cost-effective so our customers can focus on their patients. We work with pharmacies, hospitals, doctor’s offices, surgery centers and clinical labs- basically anywhere healthcare services are offered. As a leading provider of products and services in the healthcare supply chain, we have the broadest view of healthcare in the industry: We have more than 30,000 employees with direct operations around the world We deliver products and services to 40,000 customers at 60,000 locations daily 86 percent of hospitals in the U.S. use Cardinal Health products and services We supply pharmaceuticals to fill 25 percent of branded prescriptions in the U.S. In fact, a third of all distributed pharmaceutical, laboratory and medical products in the U.S. and Puerto Rico flow through the Cardinal Health supply chain. We are proud to be #21 on the Fortune 500 list
  2. Cardinal Health is committed to using our deep understanding of healthcare to deliver inventive and meaningful and solutions that make healthcare more cost-effective. As a result, our customers have more time to focus on what matters most – their patients.
  3. Our position within healthcare is very unique. We have the broadest perspective of the entire healthcare system by looking across medical and pharmaceutical manufacturers to acute care, ambulatory care and retail providers. This view allows us to understand the increasing complexity of activities across the entire continuum of care. We also focus in on each customer segment and class of trade. We have greater, deeper understanding of our customers' needs, issues and pain points. We are in the physician’s office, the lab, the hospital, the pharmacy and the retail business. We improve the total cost of healthcare. We do this not only by efficiently managing a complex supply system, but also by improving quality, helping to reduce errors and effectively aggregating supply and demand. The by-product of this is that we are able to give providers more time to focus on caring for their patients while we focus on the supply chain.
  4. 10
  5. Copy conceptual architecture diagram from the Concept Analysis Document (CAD)
  6. I hope you agree … Being essential to care is our privilege. That’s our tagline. And that’s our promise. Please let me know what questions we can answer for you.