Microsoft CISO argues against "digital xenophobia"
Bret Arsenault hits out at geographic data compliance differences
Microsoft's CISO Bret Arsenault decried "digital xenophobia" this week, criticising the breadth and variety of regulations and compliance measures around handling data among different countries.
Speaking at Infosecurity Europe 2017, he said:"I worry more about the digital xenophobia we see where all data needs to live within a government boundary. I worry we may go too far with it.I monitor about 350 regulations worldwide and it's the pending future ones which are the hardest to see ... Creating separate rules in every country is not economically viable."
Microsoft has already promised to write GDPRcompliance into its cloud contracts, to help customers meet the European Union's incoming stricter data protection rules governing how organisations can use and store EU citizens' data, which will homogenise data protection rules throughout the EU when it appliesin 2018.
The tougher lawaims to bring data protection legislation into line with new, previously unforeseen ways that data is now used. This will replace the UK's current Data Protection Act 1998, which was enacted following the 1995 EU Data Protection Directive. The new legislation introduces tougher fines for noncompliance and breaches, and gives people more say over what companies can do with their data.
However, the UK will leave the EU after voting for Brexit, meaning it will likely have to draw up its own data protection laws - even if similar, companies will have to deal with any differentiations between the two. Meanwhile, data location has become an issue of growing relevance to companies looking to store their data in different geographies in light of Edward Snowden's revelations about the extent of US spy hacking.
Among others, Microsoft itself opened up UK data centres last September to tout its services to public sector bodies and less cloud-friendly industries like finance. Collaboration firm Box used its alliance with IBM to allow customers to choose to store their data in different countries, allowing those wanting stricter protections to store it in Germany.
Arsenault added:"The one dream I have is that we get rid of passwords." He hopes instead that users can place their trust in devices themselves via growing use of biometrics as a measure to replace traditional credentials, despitea study revealing thatmost Brits distrust biometric security.
Application security fallacies and realities
Web application attacks are the most common vulnerability, so what is the truth about application security?Download now
Your first step researching Managed File Transfer
Advice and expertise on researching the right MFT solution for your businessDownload now
The KPIs you should be measuring
How MSPs can measure performance and evaluate their relationships with clientsDownload now
Life in the digital workspace
A guide to technology and the changing concept of workspaceDownload now