Corporate espionage is nothing new. Nevertheless, the theft of important and confidential data is a threat that cannot be ignored. In the digital age that we live in, data theft has become a more serious problem than ever before. In the past many documents were typically stored in files and stashed in boxes, perhaps in dimly lit warehouses. With today’s massive computerization however, stealing data is only a few clicks away. What makes it such a serious problem is the potential ease with which data can be pilfered. This is because virtually all our information is processed and shared via computer networks for which unauthorized access cannot be entirely prevented.
Companies and individuals alike have tried, and failed to some degree, to protect vital data despite investing in
data protection. This means that the data protection and access control mechanisms in common use are either obsolete or very ineffective. Why is it that protecting data using
password protect mechanisms or access control is not as effective as desired?
To begin with, many data protection mechanisms are just restricted to the computers in which the data is stored. Such a mechanism can offer access control to the data but only ensure its safety as long as it remains within the system. Typically, people use password protect login to prevent unauthorized access. While this is a convenient way of protecting data, all protection is lost once the data leaves the system. There are many ways through which this can happen. An unscrupulous employee can download a file, transfer it to a portable storage device, upload it to the cloud, or mail it to an email account. The moment this is done the data is exposed and there is no limit as to what can be done with it.
To augment the traditional password protect or access control methods of data protection it is prudent to apply some Digital Rights Management (DRM) controls. What DRM does is to shift protection from the computer system down to the document or file level. Therefore, even if an infringement of the system occurs or the document finds its way into the wrong hands, the recipient is automatically prevented from using the document unless the owner has authorized it.
This form of data protection is more effective than traditional access control because as history has shown, computer systems are neither invincible to hackers nor can companies effectively preclude the motives of some of their employees. Most DRM controls feature password protect mechanisms that are not exposed to the user, so documents cannot be easily decrypted and shared with unauthorized users.