SlideShare a Scribd company logo
1 of 33
James Reid & Wilkin Shum
#FUELGOOD18
YOUR PRESENTERS
JAMES REID WILKIN SHUM
IT Administrators & Tech
Consultants,
Sparkrock
#FUELGOOD18
• Discover – What data is under your control?
• Manage – Control how data is captured and used.
• Protect – Keep data out of harms way.
• Report – Collect records for auditing.
AGENDA
#FUELGOOD18
#FUELGOOD18
Discover
#FUELGOOD18
What Data is Important?
Personal Information
• PIPEDA – legislation defining responsibilities and penalties regarding personal information.
Health Information
• PHIPA – legislation defining responsibilities and penalties regarding health/medical information.
GDPR (General Data Protection Regulation)
• Protecting personal data by design and default.
#FUELGOOD18
Factors to Determine If Your Data is Part of These Acts
• The sensitivity of the information involved in the breach.
• The probability that the information has been, is being, could be or will be misused.
• Essentially, any data that could be used to identify an individual could be considered of
"significant harm".
#FUELGOOD18
Where is your Data?
• Need to understand where data is kept to protect it.
• Is it only in once place? Or is it being duplicated and kept elsewhere?
• If on the Cloud, where is that info kept? If it crosses borders how does
that change liability?
• Where are the scheduled backups kept?
#FUELGOOD18
On-Premise
SQL Server
• Primary place for data storage: database servers (no surprise here…)
• Need to understand how systems function & which database they use for specific data.
Users Machines
• It’s much more difficult to centrally manage what data could be kept on a user’s machine.
• System Center allows for scanning for specific data on user’s machines.
#FUELGOOD18
Cloud
• Data is not necessarily all kept in a single location.
• Integrated tools allow for easier management with the complexities of how Cloud vs. On-premise
works.
• Microsoft Azure helps you search and identify personal data with Azure Search, Azure Data
Catalog, and Azure Active Directory, along with specialized tools such as Power Query and
Query Explorer
#FUELGOOD18
What Data is Under Your Control?
#FUELGOOD18
Manage
#FUELGOOD18
ADD TITLE HERE FOR THIS SLIDE
Under GDPR individuals to whom data relates can request:
• Information on the processing of the data
• Transfer of their data to other services
• Correction of mistakes in their data
• Restriction of processing certain data in certain cases
Requests must be processed within fixed period of times
#FUELGOOD18
Data Governance
• You need to understand what types of personal data your organization
processes, how, and for what purpose.
• A data governance plan can help define policies, roles, and responsibilities for
the access, management, and use of personal data.
#FUELGOOD18
Data in Use
• We limit the amount of people and access time
• Application level access
• Encryption Management
#FUELGOOD18
Data In Transit
• Limited the path when data flow though the network
• Manage users devices
#FUELGOOD18
Data At Rest
• Securely store data
• Servers
• Client devices
• Cloud
• Data Separation
• Storage Location (physical)
• Encryption Key Management
#FUELGOOD18
Cloud Tools
• Azure Data Factory and Azure HDInsight help you trace and locate personal data.
• The Azure infrastructure can host customized privacy notices to help meet GDPR notification requirements.
• Azure Active Directory enables requesting and obtaining consent to use of data, and Azure SQL Database
can be used to document data subjects who have granted affirmative consent.
• Inaccurate or incomplete personal data can be identified and rectified using Azure Search, Azure Active
Directory, Azure SQL Explorer, and Query Explorer.
#FUELGOOD18
Protect
#FUELGOOD18
Protecting Your Data
• Potential risks could range from physical intrusions to hackers
to rogue employees to accidental loss.
• Risk Management Plans and risk mitigating steps such as
password protection, audit logs, and encryption can prevent
losses & ensure compliance.
• Don’t forget about physical security!
#FUELGOOD18
Be Proactive!
#FUELGOOD18
On-Premise Tools
• Encryption from Data at Rest to Data in Use to Data in Transit
• SQL Dynamic Data Masking to hide sensitive information by default.
• Device protection
• Bit Locker
• Password policies and strength requirements.
• Anti-virus, spam filter
• Network device
• Firewall: DDOS, Anti-virus detection, Certificate Inspection, Rules…etc
• VPN: Site to Site VPN, Client to Site VPN..etc
• Switches: VLAN, Port access control, RADIUS…etc
#FUELGOOD18
On-Premise Monitoring
• Monitoring and control over your network infrastructure, virtual machines, as well as
end-users’ computers and other devices.
• All data access permissions should be regularly checked and implemented using a
minimal access by default methodology.
• Create disaster recovery plan and regularly practice
#FUELGOOD18
Cloud Tools and Monitoring
Microsoft Azure Services: developed with Microsoft Secure Development Lifecycle, including
privacy-by-design & privacy-by-default methodologies.
Azure & related tools: comply with GDPR data protection requirements by providing ways to secure
personal data in rest and transit, detect and respond to data breaches, and facilitate security
measures.
Azure Security Center: prevents & detects threats with Security Health Monitoring & Security
Incident Response Management tools that monitor traffic, collect logs, and analyze data sources.
#FUELGOOD18
Cloud Tools and Monitoring
• Single Sign On and Two Forms Authentication
• Devices Removal practise
• All data access permissions should be regularly checked and implemented using
a minimal access by default methodology.
#FUELGOOD18
Report
#FUELGOOD18
Record Keeping
Organizations keeping personal data will need to keep detailed records in order to be compliant &
keep records on:
• Reason for processing data
• Type of personal data processed
• Third parties with whom data is shared
• Personal data of countries involved & changes in their laws
• Organizational & technical security measures
• Data retention times applicable to various datasets
#FUELGOOD18
On-Premise
SQL Server Auditing
• Audit tables that contain personal information as well as database level logins, configuration changes and schema
changes.
• Targeted auditing can be a lot more effective and practical that auditing the entire database.
Access Auditing
• Audit system access
• Audit on users access
Documentations
• Inventory, data, users device, network devices, permissions
• Disaster Recovery Plan, procedure, update, and practice result.
#FUELGOOD18
Cloud
• Azure Active Directory logs detail sign-in activity and
application usage.
• Log Analytics can aggregate and analyze Windows
Event logs, IIS logs, and Syslogs.
• Azure Monitor helps track API calls in customers’
Azure resources.
• Azure Security Center helps collect and review
security logs across Azure applications and services.
• Azure Diagnostics provides access to Event logs for
Azure VMs.
• Azure Storage Analytics can trace data requests made
against Azure Storage.
#FUELGOOD18
#FUELGOOD18
THANK YOU!
James Reid - Wilkin Shum
jreid@sparkrock.com - wshum@sparkrock.com
All presentations will be made available after the conference
#FUELGOOD18
Please take 5mins to fill out
your session evaluations
One lucky winner will win
an Amazon Echo!
#FUELGOOD18
www.sparkrock.com @sparkrockinc
Nonprofit, Human Services & K12
software to help you serve more
people, with less effort, stress &
expense.

More Related Content

What's hot

What's hot (20)

Webinar: Practical Technology Playbook for the GDPR
Webinar: Practical Technology Playbook for the GDPRWebinar: Practical Technology Playbook for the GDPR
Webinar: Practical Technology Playbook for the GDPR
 
Tackling the GDPR Dell EMC Index Engines Webinar
Tackling the GDPR Dell EMC Index Engines WebinarTackling the GDPR Dell EMC Index Engines Webinar
Tackling the GDPR Dell EMC Index Engines Webinar
 
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy ComplianceCorporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
 
Database auditing essentials
Database auditing essentialsDatabase auditing essentials
Database auditing essentials
 
Supporting GDPR Compliance through Data Classification
Supporting GDPR Compliance through Data ClassificationSupporting GDPR Compliance through Data Classification
Supporting GDPR Compliance through Data Classification
 
Protecting the Crown Jewels from Devastating Data Breaches
Protecting the Crown Jewels from Devastating Data BreachesProtecting the Crown Jewels from Devastating Data Breaches
Protecting the Crown Jewels from Devastating Data Breaches
 
Information Governance Maturity for Financial Services
Information Governance Maturity for Financial ServicesInformation Governance Maturity for Financial Services
Information Governance Maturity for Financial Services
 
Sensitive data
Sensitive dataSensitive data
Sensitive data
 
Popi and Sharepoint 2010
Popi and Sharepoint 2010Popi and Sharepoint 2010
Popi and Sharepoint 2010
 
Data Security
Data SecurityData Security
Data Security
 
The Impact of Cloud: Cloud Computing Security and Privacy
The Impact of Cloud: Cloud Computing Security and PrivacyThe Impact of Cloud: Cloud Computing Security and Privacy
The Impact of Cloud: Cloud Computing Security and Privacy
 
Eight principles of consumer data privacy
Eight principles of consumer data privacyEight principles of consumer data privacy
Eight principles of consumer data privacy
 
Personal data on the blockchain and GDPR compatibility
Personal data on the blockchain and GDPR compatibility Personal data on the blockchain and GDPR compatibility
Personal data on the blockchain and GDPR compatibility
 
Edge pereira oss304 tech ed australia regulatory compliance and microsoft off...
Edge pereira oss304 tech ed australia regulatory compliance and microsoft off...Edge pereira oss304 tech ed australia regulatory compliance and microsoft off...
Edge pereira oss304 tech ed australia regulatory compliance and microsoft off...
 
Jadu GDPR guide: A easy to follow guide for Digital Service Managers and Webs...
Jadu GDPR guide: A easy to follow guide for Digital Service Managers and Webs...Jadu GDPR guide: A easy to follow guide for Digital Service Managers and Webs...
Jadu GDPR guide: A easy to follow guide for Digital Service Managers and Webs...
 
Security&Governance
Security&GovernanceSecurity&Governance
Security&Governance
 
Symantec Data Insight 4.0 July 2013
Symantec Data Insight 4.0 July 2013Symantec Data Insight 4.0 July 2013
Symantec Data Insight 4.0 July 2013
 
EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)
 
Cleaning up Redundant, Obsolete and Trivial Data to Reclaim Capacity and Mana...
Cleaning up Redundant, Obsolete and Trivial Data to Reclaim Capacity and Mana...Cleaning up Redundant, Obsolete and Trivial Data to Reclaim Capacity and Mana...
Cleaning up Redundant, Obsolete and Trivial Data to Reclaim Capacity and Mana...
 
Data Discovery Automation: How to Save Time & Protect Customer Data
Data Discovery Automation: How to Save Time & Protect Customer DataData Discovery Automation: How to Save Time & Protect Customer Data
Data Discovery Automation: How to Save Time & Protect Customer Data
 

Similar to Fuel Good 2018: Is your Nonprofit at Risk? Security and Privacy Best Practices

Lecture Data Classification And Data Loss Prevention
Lecture Data Classification And Data Loss PreventionLecture Data Classification And Data Loss Prevention
Lecture Data Classification And Data Loss Prevention
Nicholas Davis
 
Data Classification And Loss Prevention
Data Classification And Loss PreventionData Classification And Loss Prevention
Data Classification And Loss Prevention
Nicholas Davis
 
Lecture data classification_and_data_loss_prevention
Lecture data classification_and_data_loss_preventionLecture data classification_and_data_loss_prevention
Lecture data classification_and_data_loss_prevention
Nicholas Davis
 
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Ragnar Heil
 

Similar to Fuel Good 2018: Is your Nonprofit at Risk? Security and Privacy Best Practices (20)

Ease out the GDPR adoption with ManageEngine
Ease out the GDPR adoption with ManageEngineEase out the GDPR adoption with ManageEngine
Ease out the GDPR adoption with ManageEngine
 
Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)
 
Data compliance - get it right the first time (Full color PDF)
Data compliance - get it right the first time (Full color PDF)Data compliance - get it right the first time (Full color PDF)
Data compliance - get it right the first time (Full color PDF)
 
Data compliance - get it right the first time (Black/White printable PDF)
Data compliance - get it right the first time (Black/White printable PDF)Data compliance - get it right the first time (Black/White printable PDF)
Data compliance - get it right the first time (Black/White printable PDF)
 
GDPR Part 2: Quest Relevance
GDPR Part 2: Quest RelevanceGDPR Part 2: Quest Relevance
GDPR Part 2: Quest Relevance
 
Compliance regulations with Data Centric Security | Seclore
Compliance regulations with Data Centric Security | SecloreCompliance regulations with Data Centric Security | Seclore
Compliance regulations with Data Centric Security | Seclore
 
Lecture Data Classification And Data Loss Prevention
Lecture Data Classification And Data Loss PreventionLecture Data Classification And Data Loss Prevention
Lecture Data Classification And Data Loss Prevention
 
Data Classification And Loss Prevention
Data Classification And Loss PreventionData Classification And Loss Prevention
Data Classification And Loss Prevention
 
Lecture data classification_and_data_loss_prevention
Lecture data classification_and_data_loss_preventionLecture data classification_and_data_loss_prevention
Lecture data classification_and_data_loss_prevention
 
How MongoDB can accelerate a path to GDPR compliance
How MongoDB can accelerate a path to GDPR complianceHow MongoDB can accelerate a path to GDPR compliance
How MongoDB can accelerate a path to GDPR compliance
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
 
Improve IT Security and Compliance with Mainframe Data in Splunk
Improve IT Security and Compliance with Mainframe Data in SplunkImprove IT Security and Compliance with Mainframe Data in Splunk
Improve IT Security and Compliance with Mainframe Data in Splunk
 
Aligning Application Security to Compliance
Aligning Application Security to ComplianceAligning Application Security to Compliance
Aligning Application Security to Compliance
 
Flash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRFlash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPR
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
 
How Cloudera SDX can aid GDPR compliance
How Cloudera SDX can aid GDPR complianceHow Cloudera SDX can aid GDPR compliance
How Cloudera SDX can aid GDPR compliance
 
MongoDB.local Sydney: The Changing Face of Data Privacy & Ethics, and How Mon...
MongoDB.local Sydney: The Changing Face of Data Privacy & Ethics, and How Mon...MongoDB.local Sydney: The Changing Face of Data Privacy & Ethics, and How Mon...
MongoDB.local Sydney: The Changing Face of Data Privacy & Ethics, and How Mon...
 
Global Data Privacy Regulation
Global Data Privacy RegulationGlobal Data Privacy Regulation
Global Data Privacy Regulation
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 

More from Sparkrock

More from Sparkrock (20)

Fuel Good 2018: The Framework for Funding Your Organization
Fuel Good 2018: The Framework for Funding Your OrganizationFuel Good 2018: The Framework for Funding Your Organization
Fuel Good 2018: The Framework for Funding Your Organization
 
Fuel Good 2018: Kickoff
Fuel Good 2018: Kickoff Fuel Good 2018: Kickoff
Fuel Good 2018: Kickoff
 
Fuel Good 2018: The Power of K12 Reporting
Fuel Good 2018: The Power of K12 Reporting Fuel Good 2018: The Power of K12 Reporting
Fuel Good 2018: The Power of K12 Reporting
 
Fuel Good 2018: What's New and Coming Up in Applicant Tracking?
Fuel Good 2018: What's New and Coming Up in Applicant Tracking?Fuel Good 2018: What's New and Coming Up in Applicant Tracking?
Fuel Good 2018: What's New and Coming Up in Applicant Tracking?
 
Fuel Good 2018: WHat's New and Coming Up in Employee Scheduling?
Fuel Good 2018: WHat's New and Coming Up in Employee Scheduling?Fuel Good 2018: WHat's New and Coming Up in Employee Scheduling?
Fuel Good 2018: WHat's New and Coming Up in Employee Scheduling?
 
Fuel Good 2018: What's New and Coming Up in Sparkrock Workforce?
Fuel Good 2018: What's New and Coming Up in Sparkrock Workforce?Fuel Good 2018: What's New and Coming Up in Sparkrock Workforce?
Fuel Good 2018: What's New and Coming Up in Sparkrock Workforce?
 
Fuel Good 2018: What's New and Coming Up in Sparkrock Finance?
Fuel Good 2018: What's New and Coming Up in Sparkrock Finance?Fuel Good 2018: What's New and Coming Up in Sparkrock Finance?
Fuel Good 2018: What's New and Coming Up in Sparkrock Finance?
 
Fuel Good 2018: What's New and Coming Up in D365 CRM?
Fuel Good 2018: What's New and Coming Up in D365 CRM?Fuel Good 2018: What's New and Coming Up in D365 CRM?
Fuel Good 2018: What's New and Coming Up in D365 CRM?
 
Fuel Good 2018: What's New in Overtime, ROEs & Mass Changes?
Fuel Good 2018: What's New in Overtime, ROEs & Mass Changes?Fuel Good 2018: What's New in Overtime, ROEs & Mass Changes?
Fuel Good 2018: What's New in Overtime, ROEs & Mass Changes?
 
Fuel Good 2018: What's New and Coming Up in Sparkrock for K12 Organizations?
Fuel Good 2018: What's New and Coming Up in Sparkrock for K12 Organizations?Fuel Good 2018: What's New and Coming Up in Sparkrock for K12 Organizations?
Fuel Good 2018: What's New and Coming Up in Sparkrock for K12 Organizations?
 
Fuel Good 2018: Workforce Management Pre-Conference Training
Fuel Good 2018: Workforce Management Pre-Conference TrainingFuel Good 2018: Workforce Management Pre-Conference Training
Fuel Good 2018: Workforce Management Pre-Conference Training
 
Fuel Good 2018: Finance Management Pre-Conference Training
Fuel Good 2018: Finance Management Pre-Conference TrainingFuel Good 2018: Finance Management Pre-Conference Training
Fuel Good 2018: Finance Management Pre-Conference Training
 
Fuel Good 2018: Jet Reports Pre-Conference Training
Fuel Good 2018: Jet Reports Pre-Conference TrainingFuel Good 2018: Jet Reports Pre-Conference Training
Fuel Good 2018: Jet Reports Pre-Conference Training
 
Fuel Good 2018: Finding Hidden Value in your HR and Finance Documents
Fuel Good 2018: Finding Hidden Value in your HR and Finance Documents Fuel Good 2018: Finding Hidden Value in your HR and Finance Documents
Fuel Good 2018: Finding Hidden Value in your HR and Finance Documents
 
Fuel Good 2018: Performance-based Budgeting with Questica
Fuel Good 2018: Performance-based Budgeting with QuesticaFuel Good 2018: Performance-based Budgeting with Questica
Fuel Good 2018: Performance-based Budgeting with Questica
 
Fuel Good 2018: Upgrades Made Easy: The Canadian Museum of History
Fuel Good 2018: Upgrades Made Easy: The Canadian Museum of HistoryFuel Good 2018: Upgrades Made Easy: The Canadian Museum of History
Fuel Good 2018: Upgrades Made Easy: The Canadian Museum of History
 
Fuel Good 2018: Strategic Funding Models
Fuel Good 2018: Strategic Funding Models Fuel Good 2018: Strategic Funding Models
Fuel Good 2018: Strategic Funding Models
 
Fuel Good 2018: Filling the Fundraising Gaps: The Decline of Granting & Rise ...
Fuel Good 2018: Filling the Fundraising Gaps: The Decline of Granting & Rise ...Fuel Good 2018: Filling the Fundraising Gaps: The Decline of Granting & Rise ...
Fuel Good 2018: Filling the Fundraising Gaps: The Decline of Granting & Rise ...
 
Fuel Good 2018: Jet Professional 2018: New Jet Fuel for your Reports
Fuel Good 2018: Jet Professional 2018: New Jet Fuel for your ReportsFuel Good 2018: Jet Professional 2018: New Jet Fuel for your Reports
Fuel Good 2018: Jet Professional 2018: New Jet Fuel for your Reports
 
Fuel Good 2018: The Foolproof Guide to Transitioning to an Integrated System
Fuel Good 2018: The Foolproof Guide to Transitioning to an Integrated SystemFuel Good 2018: The Foolproof Guide to Transitioning to an Integrated System
Fuel Good 2018: The Foolproof Guide to Transitioning to an Integrated System
 

Recently uploaded

Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Recently uploaded (20)

MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Quantum Leap in Next-Generation Computing
Quantum Leap in Next-Generation ComputingQuantum Leap in Next-Generation Computing
Quantum Leap in Next-Generation Computing
 
JohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptx
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
ChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps ProductivityChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps Productivity
 
Choreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringChoreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software Engineering
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Modernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaModernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using Ballerina
 
Decarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational PerformanceDecarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational Performance
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
 
JavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate GuideJavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate Guide
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDM
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 

Fuel Good 2018: Is your Nonprofit at Risk? Security and Privacy Best Practices

  • 1. James Reid & Wilkin Shum
  • 2. #FUELGOOD18 YOUR PRESENTERS JAMES REID WILKIN SHUM IT Administrators & Tech Consultants, Sparkrock
  • 3. #FUELGOOD18 • Discover – What data is under your control? • Manage – Control how data is captured and used. • Protect – Keep data out of harms way. • Report – Collect records for auditing. AGENDA
  • 6. #FUELGOOD18 What Data is Important? Personal Information • PIPEDA – legislation defining responsibilities and penalties regarding personal information. Health Information • PHIPA – legislation defining responsibilities and penalties regarding health/medical information. GDPR (General Data Protection Regulation) • Protecting personal data by design and default.
  • 7. #FUELGOOD18 Factors to Determine If Your Data is Part of These Acts • The sensitivity of the information involved in the breach. • The probability that the information has been, is being, could be or will be misused. • Essentially, any data that could be used to identify an individual could be considered of "significant harm".
  • 8. #FUELGOOD18 Where is your Data? • Need to understand where data is kept to protect it. • Is it only in once place? Or is it being duplicated and kept elsewhere? • If on the Cloud, where is that info kept? If it crosses borders how does that change liability? • Where are the scheduled backups kept?
  • 9. #FUELGOOD18 On-Premise SQL Server • Primary place for data storage: database servers (no surprise here…) • Need to understand how systems function & which database they use for specific data. Users Machines • It’s much more difficult to centrally manage what data could be kept on a user’s machine. • System Center allows for scanning for specific data on user’s machines.
  • 10. #FUELGOOD18 Cloud • Data is not necessarily all kept in a single location. • Integrated tools allow for easier management with the complexities of how Cloud vs. On-premise works. • Microsoft Azure helps you search and identify personal data with Azure Search, Azure Data Catalog, and Azure Active Directory, along with specialized tools such as Power Query and Query Explorer
  • 11. #FUELGOOD18 What Data is Under Your Control?
  • 13. #FUELGOOD18 ADD TITLE HERE FOR THIS SLIDE Under GDPR individuals to whom data relates can request: • Information on the processing of the data • Transfer of their data to other services • Correction of mistakes in their data • Restriction of processing certain data in certain cases Requests must be processed within fixed period of times
  • 14. #FUELGOOD18 Data Governance • You need to understand what types of personal data your organization processes, how, and for what purpose. • A data governance plan can help define policies, roles, and responsibilities for the access, management, and use of personal data.
  • 15. #FUELGOOD18 Data in Use • We limit the amount of people and access time • Application level access • Encryption Management
  • 16. #FUELGOOD18 Data In Transit • Limited the path when data flow though the network • Manage users devices
  • 17. #FUELGOOD18 Data At Rest • Securely store data • Servers • Client devices • Cloud • Data Separation • Storage Location (physical) • Encryption Key Management
  • 18. #FUELGOOD18 Cloud Tools • Azure Data Factory and Azure HDInsight help you trace and locate personal data. • The Azure infrastructure can host customized privacy notices to help meet GDPR notification requirements. • Azure Active Directory enables requesting and obtaining consent to use of data, and Azure SQL Database can be used to document data subjects who have granted affirmative consent. • Inaccurate or incomplete personal data can be identified and rectified using Azure Search, Azure Active Directory, Azure SQL Explorer, and Query Explorer.
  • 20. #FUELGOOD18 Protecting Your Data • Potential risks could range from physical intrusions to hackers to rogue employees to accidental loss. • Risk Management Plans and risk mitigating steps such as password protection, audit logs, and encryption can prevent losses & ensure compliance. • Don’t forget about physical security!
  • 22. #FUELGOOD18 On-Premise Tools • Encryption from Data at Rest to Data in Use to Data in Transit • SQL Dynamic Data Masking to hide sensitive information by default. • Device protection • Bit Locker • Password policies and strength requirements. • Anti-virus, spam filter • Network device • Firewall: DDOS, Anti-virus detection, Certificate Inspection, Rules…etc • VPN: Site to Site VPN, Client to Site VPN..etc • Switches: VLAN, Port access control, RADIUS…etc
  • 23. #FUELGOOD18 On-Premise Monitoring • Monitoring and control over your network infrastructure, virtual machines, as well as end-users’ computers and other devices. • All data access permissions should be regularly checked and implemented using a minimal access by default methodology. • Create disaster recovery plan and regularly practice
  • 24. #FUELGOOD18 Cloud Tools and Monitoring Microsoft Azure Services: developed with Microsoft Secure Development Lifecycle, including privacy-by-design & privacy-by-default methodologies. Azure & related tools: comply with GDPR data protection requirements by providing ways to secure personal data in rest and transit, detect and respond to data breaches, and facilitate security measures. Azure Security Center: prevents & detects threats with Security Health Monitoring & Security Incident Response Management tools that monitor traffic, collect logs, and analyze data sources.
  • 25. #FUELGOOD18 Cloud Tools and Monitoring • Single Sign On and Two Forms Authentication • Devices Removal practise • All data access permissions should be regularly checked and implemented using a minimal access by default methodology.
  • 27. #FUELGOOD18 Record Keeping Organizations keeping personal data will need to keep detailed records in order to be compliant & keep records on: • Reason for processing data • Type of personal data processed • Third parties with whom data is shared • Personal data of countries involved & changes in their laws • Organizational & technical security measures • Data retention times applicable to various datasets
  • 28. #FUELGOOD18 On-Premise SQL Server Auditing • Audit tables that contain personal information as well as database level logins, configuration changes and schema changes. • Targeted auditing can be a lot more effective and practical that auditing the entire database. Access Auditing • Audit system access • Audit on users access Documentations • Inventory, data, users device, network devices, permissions • Disaster Recovery Plan, procedure, update, and practice result.
  • 29. #FUELGOOD18 Cloud • Azure Active Directory logs detail sign-in activity and application usage. • Log Analytics can aggregate and analyze Windows Event logs, IIS logs, and Syslogs. • Azure Monitor helps track API calls in customers’ Azure resources. • Azure Security Center helps collect and review security logs across Azure applications and services. • Azure Diagnostics provides access to Event logs for Azure VMs. • Azure Storage Analytics can trace data requests made against Azure Storage.
  • 31. #FUELGOOD18 THANK YOU! James Reid - Wilkin Shum jreid@sparkrock.com - wshum@sparkrock.com All presentations will be made available after the conference
  • 32. #FUELGOOD18 Please take 5mins to fill out your session evaluations One lucky winner will win an Amazon Echo!
  • 33. #FUELGOOD18 www.sparkrock.com @sparkrockinc Nonprofit, Human Services & K12 software to help you serve more people, with less effort, stress & expense.

Editor's Notes

  1. Have this slide up as people enter the room
  2. Take 5mins to give the audience a bit of background about you
  3. Have this slide up as people exit the room.