Hi, I'm Subrana Goswami, Associate Editor with Information Security Media Group. We've been discussing about data governance and how it has become all the more important stuff to discuss further on this. I have with me today Prashant Pandita, who is CISO at DriverSec. Hi Prashant, thank you so much for joining the conversation.
Hi Subrana, thanks for having me. Thank you. So Prashant, data governance has always been a challenge for CISOs, and for that matter, the security team. But I understand that COVID-19 situation has brought in challenges of shadow IT as well, which in turn results in poor data governance, since one doesn't know where all the data lies affect.
You are a CISO. What are the kind of challenges as far as data governance is concerned, because it's not something new. But I want to understand this, under COVID-19, are there any new challenges as far as data governance is concerned? Yeah, I mean, shadow IT, as we all know, and many of the sides will deal with this day and day out.
I guess shadow IT has been a problem ever since this cloud and other technologies came in place. Shadow IT is seen as a business taking a shortcut and procuring things that are easy for them to do, and they find efficiency out of it. Now talking about COVID-19, it has, I think, fast packed some of the shadow IT issues if I can put it that way. So some of the things that I have seen is, so first of all, and organizations were not ready for the entire staff to work in working.
That's in itself is a big problem. And I have seen a lot of companies asking staff to go and procure their own laptops. That's not directly shadow IT, but having their own laptops without any controls in place is one thing, which has thrown everything out of the company borders, if you like, and the controls. Secondly, it's cloud-based apps.
Many companies have, you know, an accepting way has a lot of employees to use cloud apps, which may take that out and put it somewhere in the cloud, which we don't know. And again, this is based on what I employed as and what they allowed to do. But again, we can't control everything, right? So that's one thing.
I think the other one is collaboration tools. And as you can see from the news, there are a lot of tools that are used by companies now, which weren't used before. And these collaboration tools, obviously, they have some information within them that may be sensitive to companies when they're doing collaboration activities. So that's open another challenge, I guess.
And specifically companies which are regulated by jurisdictions, et cetera. And when they embark on such collaboration tools, cloud applications, it's, I think, from a regulation point of view, they are dealing with bigger problems when all these COVID situations are down a bit. So that's, I think, those are the key ones. But the last one I'd like to add is installing free software.
So obviously people are trying to make things work and companies trying to keep the budget in control as well. And I've seen many employees come back with a suggestion saying, oh, can I use this free software instead of finding so much ambient subscription? And in most of the cases, IT is helpless, but to say yes, because under the pressure to get things working, these are, I think, some of the issues that we have seen people are dealing with relative on the remote access issue and having VPN configurations and so on and so forth. And so you mentioned about collaboration tools.
You mentioned about people downloading software to get a task done, which is absolutely essential now because you need to get the task done. So under such circumstances, how should organizations manage data governance when all this is actually a reality? And you can't really say that, okay, you are not supposed to do this. I mean, one of the things which is our soft control, I guess, it works most of the times, is that creating awareness and again, it might sound a bit of a long-term approach, but there are simple things that you can do to make employees aware that to make employees aware of the risk of basically not going into creating one items or not getting IT and look, what is the impact on data, but also what is the impact on privacy of the one information, of the staff information.
So making them aware of this risk, I think it's a key factor. There is a major need for them to be aware of these areas. So it may not be a lengthy process to go through pages and read out stuff. It could be like small messages which are quite impacting, just letting them know through a wider broadcast saying these are the risks that you could be looking at if you don't follow the rules and regulations that are required.
Secondly, I think, again, from the technology point of view, there are a lot of things that companies are doing, which I have seen first and where they have implemented simple network analyzes at the ingress part, ingress part of the network. So what that means is they're trying to monitor as much as they can as to what is going in and out of the network and see how that can be managed, because ultimately, as we all know, we can only manage what we know, which we don't know we can't manage. So as long as you have that footprint of data, the existing footprint and then immediately tell a footprint after this COVID-19, as long as you're aware, you can manage that. At least you get a sense of where it's going and how it's managed, then you can put controls accordingly.
One more thing that I've seen companies doing, and again, it's a bit of a staggered approach with this one is something called CASB. So what that does is it creates a centralized policy framework for all the connections going in and out of the cloud. So, for example, if our organization is using cloud, it could be an existing model or the new setup that employees have gone and done. It creates a central policy location where you can monitor actually the activities.
Question, CASB, your network detectors, all these are not new solutions. Things have been there in the market and I'm sure companies have been implementing this. Still, data governance has been a problem. It's not that it has now been a problem.
So, what is that they haven't been able to solve even with these technologies in place? Why is that data governance continues to be a problem? So, if I had to talk about corporate environment, obviously, there are various business units, and then there is IT, which is seen as the main function to run the business. From our account of view, I think for organizations who are not mature in data governance, there is a gap between IT and the business.
By that, what I mean is IT is not close to business in understanding what their requirements are. So, then the business might feel okay, it's too hard to go ahead and get them to agree on things that we need to do. Let's just do it on our own and make a easy way out of. So, I think that's one of the biggest problems.
Engagement between the teams and the IT or the business within the IT. So, to address that, I think there should be a collaborative work between the business units as well as the IT. Sounds simple to say, but I guess it has to happen. Otherwise, you won't know the business requirements are moving forward.
Secondly, I guess if the gap is reduced, then in this age, you can't say that, okay, shadow IT is totally out of question. We can't support that. We can't move ahead of that. Whatever you've done, let's scrap it and start over again.
That's not going to happen for sure. When I said collaborative solution, there could be a way where IT understands what business needs. If there are existing shadow IT configurations that have been used, they could come to a solution where they can work out a core governance model. I've seen that working in some organizations which are a bit more mature in data governance space, where the business would have certain responsibilities towards managing that of particular services.
When we talk about shadow IT, for example, then IT would have certain aspects. So, in that way, the IT can manage the required controls. It could be security controls or IT-red controls to manage that particular solution. And from a business point of view, business is responsible to manage the relationship with the vendor, or whoever they are dealing with, to make sure that there is a smooth flow of identity.
But in terms of data security, et cetera, IT would be responsible to, you know, deliver that to the business and it can help hold the vendor accountable to that. I've also seen in some areas where they talk about business solutions, where they might, for a particular business unit, they might ask that particular business to manage that fully, depending on the risk, or they might use a core governance model. So, that also is possible. But ultimately, to get everything going, what I've mentioned in all my points, there should be a policy framework which enforces this right from the top.
Without which, I guess, if the message is not clear, people are not going to be sure as to what kind of behavior is expected out of them. And then, there is no standard for obesity. And that's why the policies are. And again, I'll come back to my points on creating awareness trainings and, you know, having necessary monitoring identification in place, where the IT story is actually aware of what is happening in the business and where the shadow IT problem lies, so they can understand accordingly.
Considering this is the new norm you're going ahead, do you think companies need to revisit their data governance policies or do you spoke about core governance? Can you elaborate a bit on that as well? Yeah, to answer your first question, yes. I think they need to leave within data governance because every time I hear about some news, some of the telcos in Australia have said that remote working is going to be the new norm moving forward.
They might cut down office spaces and things like that because now that they're figured out that people can work remotely without having an office space, why wouldn't they embark on such an initiative, which also saves them calls, but also makes sure that services are delivered. So it's definitely not a governance policy needs to be revisited. So along with data governance, it's also not a management understanding. Your data architecture, where it's residing, where it's going to reside, how is how it will be required moving forward for people who are working remotely, so on and so forth.
So I think that has to be in place. But in terms of core governance, what I mean by that is, for example, a business goes and procures something. They take the accountability to make sure that the service is delivered as per the requirements or as stated by the vendor. Traditionally, IT goes and procures services and IT are held responsible to deliver this as a service.
So I'm saying, let's just flip that around and make business responsible for shadow IT if that is what they want. In that IT should be responsible for the overall governance on the controls as well as compliance requirements, you know, over on that security. So there are many organizations who have failed compliance. We just compliance regimes that they need to follow, which is because of shadow IT.
And I've witnessed that first time in my audits where some data, which is one of the scope for the assessments or compliance audits, have been deciding on cloud environments, which are not in scope. And these things are like surprises when we do the audits. But again, if IT is across this, then they can make sure that compliance will come and sign post from these vendors. And if that's not right, that's not right solution, then we track that with the business and take necessary actions.
Fantastic. Thank you so much, Prashant, for sharing your thoughts on this. No problem. You've been listening to Prashant, haven't got it for IceMG, this is a good news one.
Thank you.