你的数据真的安全吗?

一个戴眼镜的男人对着镜头微笑
2024年8月30日

数据安全, sovereignty and integrity are business-critical and thus always need to be transparent.

触屏设备上一只手的特写

The past 50 years have been heavily marked by fast technological advancements that have had an extraordinary impact on our daily lives. In the 1970s, computers and the internet were things only governmental institutions were using! There was no on-demand television or instant messaging – people had to keep track of their favorite TV programs in newspapers and had to either make a phone call or meet up personally to talk about their day. Today, 我们的设备是超级强大的,我们的互联网连接是闪电般的速度, 所有的价格都是可以承受的. 人类比以往任何时候都更加紧密地联系在一起, but how does this impact our private lives and the security of our digital identities? 在这样一个快节奏的世界里,你如何确保你的数据是你自己的?

数据安全、完整性和主权之间的区别是什么?

让我们首先对关键术语有一个共同的理解:

数据安全 保护数据不被访问的过程是否存在, manipulated, 或在其生命周期内被未经授权的人员或应用程序损坏. 它包括数据加密和散列等活动.

数据完整性 (also called data quality) indicates how consistent and untampered-with a set of data is, 不管存储在哪里和如何存储.

数据主权 makes sure that your data is subject only to the laws of the country in which it is located.

我们的社交媒体账号之间, the online shops in which we’ve saved our payment data for faster transaction processing and the occasional sweepstake we’ve shared our personal address with in case we win something, 我们往往会忘记我们会有多妥协. 即使我们不是大型安全漏洞的直接受害者,比如 2013年雅虎安全漏洞, 在此期间,多达30亿个账户被泄露, the data we willingly share with multiple platforms is often shared with or sold to third parties – and often isn’t anonymized.

错误处理或损坏数据的危险是什么?

最近的一次峰会 数据安全和主权领导者 重点讨论我们在这里讨论的一些话题. 在录音采访中,云的领导 NXO, OVHcloud and 阿尔卡特朗讯企业 came together to discuss what it takes to guarantee total and transparent data sovereignty.

Sylvain Rouri
, OVHcloud的首席销售官他将数据比作一辆锁着的自行车:“加密只是你自行车上的锁. 它不能防止自行车被偷.” He also made it abundantly clear that true data sovereignty can only be achieved when we know and understand all the layers. 我们需要问“谁在处理数据。?、“数据存储在哪里??以及“数据是如何管理的。?”. If these questions do not receive clear answers, it should be considered a red flag.

处理不当的危险, leaking, or corrupting someone else’s data have reputational implications as well as legal repercussions. The security breach Target jeopardized approximately 40 million credit and debit cards, resulting in monumental sales decline and thousands of employees losing their jobs. 花了数年时间才挽回损失.

真正的数据主权面临的三大挑战

穆萨Zaghdoud, 阿尔卡特朗讯企业云通信事业部执行副总裁, highlighted the risk by noting that if you communicate, you’re exchanging data. He and Rouri agreed that very few certifications out there truly regulate and guarantee data sovereignty. 尽管法国以身作则 ANSSI SecNumCloud认证, there remains no centralized certification that guarantees data sovereignty on a European level.

Zaghdoud noted three big challenges for vendors when complying with regulations. First, make sure to use best-in-class encryption mechanisms and state-of-the-art technology. 第二,完全保护所有数据,无论它位于何处或从何处访问. 最后,也许也是最重要的一点,保持流畅和直观的用户体验.

Understanding the layers of a true sovereign solution and how they come together is what seems to be the answer. 从头开始, the infrastructure needs to comply to all local and international regulations and standards. The solution you are building on top of it then needs to meet all security standards for encryption, 技术和互联互通. Data needs to be protected not only when it is stored, but also when it is in transit. 最后一块拼图是客户层面的集成商, 谁必须确保自己的数据得到保护, regulate how and if it is shared with third parties and that the solution is deployed correctly.

信任和专业知识是数据主权的基础

With every new encryption method and technology comes the need to adjust existing regulations and laws. 有时,这些调整是次要的,很容易执行, but a change in technology can also lead to a complete obsoletion of prior laws. The latter situation has a bewildering impact on all three layers – infrastructure, solution, 和部署. 弗朗索瓦Guiraud, 业务拓展主管 & 法国NXO的数字化转型他说,服务提供商和集成商最接近客户. They need to work hard to earn accolades and position themselves as trusted advisors.

It is a constant war of attrition to keep ahead of ever-changing trends and technologies, 总是平衡新事物和成熟事物. So long as this is controllable by local authorities, we can determine data sovereignty. The real confusion starts when we start deploying solutions from vendors across the globe, 或者更具体地说, 当使用欧洲总部设在美国的企业管理的解决方案时.

云计算法案如何危及数据安全和数据完整性

What may seem harmless at first glance could turn out to be a serious breach of data sovereignty and integrity. 2001年,美国政府颁布了《火狐体育手机官网》 Patriot Act授权他们强制访问存储在美国境内的任何数据. 这很容易通过将数据托管在另一个国家来解决, 难道不是因为它的延伸范围很麻烦吗 云法案(2018年); which extended  the Patriot Act from US-only to worldwide reach if the enterprise handling the data has a US headquarters.

除了法规之外, 法律与技术突破, 意想不到的全球发展, crises or collapsing markets can cause unforeseen sanctions that could inflict grievous wounds on your organization. OVHcloud的Rouri概括了这一点, “只有完全理解所有层面,你才能获得完全的信任. 如果不这样做,则无法重新部署、保护、扩展或恢复. 你基本上是你所选择的解决方案的囚徒.”

总之, 如果你真的想确保你的数据是安全的, 主权和不受干扰, 检查您正在寻找的解决方案的所有层. 确保每件事都清楚地摆在你面前. 涵盖从解决方案托管的方式和位置到开发人员的所有内容, 管理和部署它. 限制对第三方的访问,并确保何时必须授予访问权限, 从端到端角度来看,它是加密和安全的. 你的数据是你自己的, but it sometimes takes a bit of reading between the lines to make sure it stays that way.

 
一个戴眼镜的男人对着镜头微笑

Toni Galo

阿尔卡特朗讯企业SaaS产品营销经理

2018年,Toni开始在ALE担任业务开发经理. In 2020 he took over the position as the SaaS Product Marketing Manager with the 云通信 Business Division. 在加入ALE之前,他曾管理过国际内容创作者团队, 推出并有效推广应用程序, 帮助建立网站, market businesses and form strong and unique messaging for businesses around the globe.

Marketing is more than writing a few cool words on an image or having a movie star hold long-winded speeches about a product. 它也不仅仅是一个愿景,一个使命或一个为什么. 营销给产品, services and people a deep context and consumers a feeling and an experience they don't get anywhere else.

作者简介

Latest Blogs

拿着电话的人
Rainbow

认证如何创建透明度并保护您的数据

Certifications are good indicators to understand how your data will be protected

触屏设备上一只手的特写
业务连续性

你的数据真的安全吗?

数据安全, sovereignty and integrity are business-critical and thus always need to be transparent.

一男一女在看笔记本电脑
数字时代通信

您的数字化转型之旅需要了解什么

独自经历数字化转型可能是一项可怕的任务

一群人站在一起
业务连续性

使用认证来保护数据和提高透明度

Certifications are often a good key indicator to understand how your data is going to be protected.

Chat