securing and protecting citizens' data

6
Bob Bence CIO St. Louis County June 18, 2009

Upload: darci

Post on 24-Jan-2016

27 views

Category:

Documents


0 download

DESCRIPTION

Securing and Protecting Citizens' Data. Bob Bence CIO St. Louis County June 18, 2009. Citizen Data. Information Needing Protection Governance Policies IT Architecture. Information Needing Protection. Personal identification (SSN) Medical records Credit card Law enforcement - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Securing and Protecting Citizens' Data

Bob BenceCIO

St. Louis CountyJune 18, 2009

Page 2: Securing and Protecting Citizens' Data

Information Needing Protection Governance Policies IT Architecture

Page 3: Securing and Protecting Citizens' Data

Personal identification (SSN) Medical records Credit card Law enforcement

◦ Criminal history records◦ Finger prints

Certain addresses on real estate web site◦ Stalking victims

Page 4: Securing and Protecting Citizens' Data

Have a culture of awareness & security Compliance (HIPAA, PCI, CJIS, etc) IT Security Team Peer Reviews, Gartner Security report to IT Steering Committee

three times/yr Internal & External security audits

Page 5: Securing and Protecting Citizens' Data

Identify & label Confidential & Private information

Limit access to systems with sensitive information

No credit card numbers stored on our systems

Website privacy statement on web site Redact personal information Review web content before posting Security section in bids & RFPs

Page 6: Securing and Protecting Citizens' Data

St. Louis County E-commerce Architecture

S W EC

FW1 FW2

FW3

Web Servers

Applicat-ion

Servers

DatabaseServer

Internet

DMZ

Zone 1 Zone 2 Zone 3

FW = FirewallS = SwitchW = Web Application Firewall

• VLANS for network segmentation