Good data security means having "defensive depth" embedded in information systems, says Alain Sheer, an attorney in the Federal Trade Commission's division of privacy and identity protection. "Relying on one defense is problematic."

Speaking at the Safeguarding Health Information Conference in Washington, Sheer gave examples of the need for multiple levels of defense. An organization, for instance, may encrypt data but have weak user authentication controls. This enables a hacker to access the encryption module and find the decryption key.

Register or login for access to this item and much more

All Information Management content is archived after seven days.

Community members receive:
  • All recent and archived articles
  • Conference offers and updates
  • A full menu of enewsletter options
  • Web seminars, white papers, ebooks

Don't have an account? Register for Free Unlimited Access