1 / 4100%
The business of handling and protecting intellectual property is a
continuous struggle between companies and cybersecurity
professionals against malicious actors. Basically, intellectual property is
a creative idea used commercially. Such examples include logos,
symbols, mechanical inventions, or patents. (Upcounsel, 2020)
Information such as this are valuable to one’s own interest to protect.
Unfortunately, malicious actors have strong motives to steal this
information for their own interest or the interests of their employer.
Some of those motivations may include retribution, financial gain, or
intelligence information.
Intellectual property theft affects all direct parties involved and
several indirect people caught in the crossfire unfortunately. Below
are some points of interests about intellectual property theft and
recommended best practices for everyone to observe.
Manage Least Privilege
Large enterprises must manage many users with complex systems
including different duties, levels of responsibility, and physical
locations. Any layer of an enterprise is prone the intellectual property
theft. Additionally, onboarding and offboarding personnel shape a
different set of challenged managers confront. It’s important for IT
management to comb through permissions and privileges of their
userbase with a fine-tooth comb. Mismanagement or oversight can
happen as well. Accounts and credentials may become orphaned,
forgotten, or lost within an organization’s system. (BeyondTrust, 2021)
Users should be able to only utilize and access only the necessary
functions of their duties. It is recommended to carefully configure
different identities such as applications, humans, or machines with
separate rules and policies from each other. It is recommended that IT
management train and educate their userbase to understand the
limitations and functions of their system accesses.
Establish Data Classification
In addition to managing privileges, data classification is a major
concern. A data classification policy establishes a framework of the
different types of data. This framework should classify data into
separate components such as sensitive, confidential, or informational. d
Segmentation provides a structure for protecting, creating, storing,
and transmitting the intellectual property data in the organization.
(Knowles, 2022) Keep the data classification policy simple with as few
classifications as possible to avoid confusion.
Enforce Data Destruction
Important intellectual property is susceptible to theft when not
handled correctly. Malicious actors may attempt to steal information
through social engineering means such as “dumpster diving” or
impersonation. When sensitive data has been deleted it may contain
remnants on a system. Creating a strong data destruction policy limits
a potential malicious actor from attaining important data sets. IT
managers should create a set of removal classifications that define the
different types of media including removable media, hard drives, and
paper-based media. (ID123, N/D) Additionally, cloud-based services
need to be addressed in relation to when in how the data is destroyed.
Different vendors and services have different policies when handling
destroying data.
Define Separate Duties/Roles
Limit the number of authorized personnel that can access the
important intellectual property. Separating the duties and roles of
employees combats against bleed over of data sets from different
departments. NIST defines separation of duties as, “. . . the principle
that no user should be given enough privileges to misuse the system
on their own. For example, the person authorizing a paycheck should
not also be the one who can prepare them.” (NIST, N/D) As previously
mentioned, different departments would not have the ability to access
or tamper other departments with a strong separation of duty policy.
One example of this in practice to prevent intellectual property theft
could be disgruntled employee attempting to retrieve a patent file on
a specific database. If the user denied entry from the start, the file is
unobtainable through those means.
Build Strong Bonds with Customers and Clientele
Oftentimes, competitors may try to contact current or former
customers and clientele with the goal learn company secrets. To
prevent this, a contract or purchase agreement should be created and
communicated with the customer. (Molinski, 2015) Ideally, this would
disincentivize a motive between the two malicious or unaware parties.
Malicious actors and customers would not be looking for a lengthy
criminal investigation or a civil lawsuit if they look do to business with
each other.
Summary
In conclusion, companies may find that intellectual property is
susceptible to theft on their databases. Listed above, were some initial
steps and best practices companies could apply to their systems to
prevent theft and protect their very important information.
Establishing proper policies and procedures to handle this data will
lead to a more robust program to combat intellectual property theft.
References
BeyondTrust. (2021) “What Is Least Privilege & Why Do You Need
It?'”
BeyondTrust
. https://www.beyondtrust.com/blog/entry/what-is-
least-privilege
Knowles, Mark. (2022) “Data Classification Policy: Definition,
Examples, & Free Template.”
Hyperproof
.
https://hyperproof.io/resource/data-classification-policy/
ID123. (N/D) “Data Destruction Policy.”
ID123
.
https://www.id123.io/compliance/data-destruction-policy/
NIST. (N/D) “Separation of Duty (SOD).”
NIST
.
https://csrc.nist.gov/glossary/term/separation_of_duty
Upcounsel. (2020) “Intellectual Theft: Everything You Need to Know.”
Upcounsel
. https://www.upcounsel.com/intellectual-theft
Students also viewed