1 / 5100%
Intellectual Property Theft
This background briefing is to explain the recent completed
investigation of how a competitor obtained copies of confidential
architectural drawings and design plans from our company. It was also
reported that another competitor disclosed that it had been sent URLs
for web pages containing links to the resort plans by an unknown
party. I will be explaining the problem of intellectual property theft.
Then address the reasonable and customary processes as well as
procedures which should be used to discourage or make it difficult for
employees, managers, and executives to inadvertently misuse and/or
steal classified information from the company. Finally, I will identify
and explain practices which we should implement in respond to this
problem. d We need to address this problem head on to stop it and
prevent it from growing.
Let us begin with understanding what the problem is. Intellectual
theft is stealing or using without permission someone else's
intellectual property, (Intellectual Theft: Everything You Need to
Know, 2020). Intellectual Theft: Everything You Need to Know (2020)
defines intellectual property as any creative or commercial innovation,
any new method that has economic value, or any distinctive mark
which might include a name, symbol, or logo that's used in commercial
practices. The intellectual property that was stolen were drawings
and design plans for future property. d At least one competitor is
known to have copies of the company's intellectual property, and
another is known to have access via a URL, but we are not sure if they
have copies even though they stated not to. No matter what it is best
to assume they have copies as well. How do we prevent this from
happening again in the present and future?
Let us investigate discussing processes and procedures to discourage
or make it difficult to inadvertently misuse and/or steal the company’s
intellectual property. With this I will be addressing data classification
and marking, separation of duties, and least privilege. De Groot
(2015) defines data classification and marking as the process of
separating and organizing data into relevant groups (“classes”) based
on their shared characteristics, such as their level of sensitivity and
the risks they present, and the compliance regulations that protect
them. Segregation of duties (SoD) is a central issue for enterprises to
ensure compliance with laws and regulations, (Ferroni, 2016). Least
privilege is the concept and practice of restricting access rights for
users, accounts, and computing processes to only those resources
absolutely required to perform routine, legitimate activities, (Miller,
2016).
A process using data classification markings within the company was
explained within the article Data Classification (Data Management): A
Complete Overview (n.d.). This article discusses four categories that
organizations use which are public, private, confidential, and
restricted. Public information is freely available and accessible to the
public without any restrictions or adverse consequences, such as
marketing material, contact information, customer service contracts,
and price lists. Internal data is low security requirements, but not
meant for public disclosure, such as client communications, sales
playbooks, and organizational charts. Confidential is sensitive data
that if compromised could negatively impact operations, including
harming the company, its customers, partners, or employees.
Restricted is highly sensitive corporate data that if compromised could
put the organization at financial, legal, regulatory, and reputational
risk. These four categories can help identify materials that is capable
of disclosing information that can be harmful to the company if it was
disclosed outside amongst those who don’t have the need to know.
Eck (2019) mentioned the following practices which are completing a
risk assessment of sensitive data, developing a formalized
classification policy, and categorizing the types of data. These
practices should contribute to the present and future establishment of
the company’s data classification and marking policy.
A procedure I want to introduce would be implementing segregation
of duties. This procedure will prevent anyone having access within
any company process to just him or herself. In essence, the physical
custody of an asset, the record keeping for it, and the authorization to
acquire or dispose of the asset should be split among different people,
(
Segregation of Duties
, 2021). This could be one of the many ways to
prevent theft or other fraudulent activities happening within the
organization. This procedure must have someone over see who has
access to documents as far as assigning personnel to manage as well
as access them. Ferroni (2016) stated a role engineering plays a
significant role in supporting SoD rules within an identity management
system, as it enforces access rights and detects conflicts as they
happen. Segregation of duties best practices are the review of current
structure, landscape, and posture within the organization, (Brown,
2016). The continue review of these practices can help maintain who
has access to materials pertaining policies, financial, personnel, and
future builds at a minimum.
Another process or procedure I want to mention is the concept of
least privilege. Before we get into this one, I would like to make sure
we do not get this mixed up with the need-to-know meaning. G
(2016) gives a good example of both as you could have a "view"
access at the "Need to Know" principal level but then the "Least
Privilege" principle mainly governs with "Write" and "Execute" bits.
This example leads me to explaining two user accounts: standard and
super. Standard user accounts, sometimes called least-privileged user
accounts (LUA) or non-privileged accounts, have a limited set of
privileges where as superuser accounts, primarily used for
administration by specialized IT employees, may have virtually
unlimited privileges, or carte blanche, over a system, (Miller, 2016).
Since our IT employees will have superuser accounts they will be the
ones creating the standard user accounts. The best practices are
suggested from Miller article What Is Least Privilege & Why Do You
Need It? (2021). Perform a privilege audit to discover, and bring
under policy management, all privileged accounts and credentials for
employees, contractors, and vendors. Remove all root and admin
access rights to servers and reduce every user to a standard user.
Segment systems and networks to broadly separate users and
processes based on different levels of trust, needs, and privilege sets.
Following these best practices will help IT department manage as well
as maintain the least privilege process and procedure.
In conclusion we cannot expect everyone to understand and know the
does as well as the do nots. The processes and procedures are here
to help manage, but someone must overlook each one from the inside
out. If changes need to me made, make them but keep in mind not
everyone will follow under just that one change. We must look at
other investigations, topics, and briefs to learn from mistakes
discussed within these writings. The practices mentioned above
should help if implanted with the response to the growing problem of
intellectual property theft. These are not the only ones, but I feel
they are a good start towards a better future of not having the
problem of intellectual property theft recurring.
References
Brown, D. (Ed.). (2016, October 13).
Segregation of Duties Best
Practices
. CompVisory.
https://compvisory.com/2016/10/13/segregation-of-duties-best-
practices/
Data Classification (Data Management): A Complete Overview
. (n.d.).
Spirion. Retrieved April 21, 2022, from https://www.spirion.com/data-
classification/
De Groot, J. (2015, January 12).
What is Data Classification? A Data
Classification Definition
. Digital Guardian.
https://digitalguardian.com/blog/what-data-classification-data-
classification-definition
Eck, T. (2019, August 9).
7 Steps to Effective Data Classification
.
EDGE Sirius; Forsythe. https://edge.siriuscom.com/security/7-steps-
to-effective-data-classification
Ferroni, S. (2016, May 19).
Implementing Segregation of Duties: A
Practical Experience Based on Best Practices
. ISACA.
https://www.isaca.org/resources/isaca-journal/issues/2016/volume-
3/implementing-segregation-of-duties-a-practical-experience-based-
on-best-practices
G, A. (2016, May 21).
CISSP Insights - Need to Know and Least
Privilege
. Www.cm-Alliance.com. https://www.cm-
alliance.com/cissp/2016/05/cissp-insights-need-know-least-privilege-
let-us-learn-something-quick-cissp-topic
Implementing Segregation of Duties: A Practical Experience Based on
Best Practices
. (n.d.). ISACA. https://www.isaca.org/resources/isaca-
journal/issues/2016/volume-3/implementing-segregation-of-duties-a-
practical-experience-based-on-best-practices
Intellectual Theft: Everything You Need to Know
. (2020, October 27).
UpCounsel. https://www.upcounsel.com/intellectual-theft
Miller, M. (2016, November 17).
What Is Least Privilege & Why Do
You Need It?
Beyondtrust.com; BeyondTrust.
https://www.beyondtrust.com/blog/entry/what-is-least-privilege
Segregation of duties
. (2021, November 7). AccountingTools.
https://www.accountingtools.com/articles/segregation-of-duties.html
Students also viewed