---
title: 3 Ways to Protect Data and Control Access to It
description: 3 Ways to Protect Data and Control Access to It
---

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/head-logo-2.svg "TowerWall")](https://towerwall.com/)

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/towerwall-logo-white-test.svg "TowerWall")](https://towerwall.com/)

- [Our Partners](https://towerwall.com/how-we-protect-you/our-technology-partners/)
- Our Solutions 
    - - Our Cybersecurity Solutions 
                  - We operationalize infosec,  
                     building security solutions that  
                     safeguard your most critical assets.
          - - [Solutions Overview](https://towerwall.com/cybersecurity-solutions/)
                  - [Risk Assessments & Security Reviews](https://towerwall.com/cybersecurity-solutions/risk-assessments-security-reviews/)
                  - [Program & Policy Development](https://towerwall.com/cybersecurity-solutions/program-policy-development/)
                  - [Incident Response & Remediation](https://towerwall.com/cybersecurity-solutions/incident-response-remediation/)
                  - [Managed Detection & Response](https://towerwall.com/cybersecurity-solutions/managed-detection-response/)
          - - [Compliance & Privacy](https://towerwall.com/cybersecurity-solutions/compliance-privacy/)
                  - [Comprehensive Security Training](https://towerwall.com/cybersecurity-solutions/comprehensive-security-training/)
                  - [Vulnerability Protection](https://towerwall.com/cybersecurity-solutions/vulnerability-protection/)
                  - [Penetration Testing](https://towerwall.com/cybersecurity-solutions/penetration-testing/)
- Virtual Security Officers 
    - - Virtual Security Officer 
                  - Leverage the experience and  
                     security acumen of Towerwall’s  
                     on-demand security experts.
          - - [Virtual Chief Information Security Officer (VCISO)](https://towerwall.com/virtual-security-officers/virtual-chief-information-security-officer-vciso/)
                  - [Virtual Data Protection Officer (vDPO)](https://towerwall.com/virtual-security-officers/virtual-data-protection-officer-vdpo/)
                  - [Virtual Chief Privacy Officer (vCPO)](https://towerwall.com/virtual-security-officers/virtual-chief-privacy-officer-vcpo/)
- We Advise 
    - - We Advise 
                  - One-size security solutions only  
                     lead to failure.
          - Industries 
                  - [Higher Education](https://towerwall.com/industries/higher-education/)
                  - [Financial Services & Banking](https://towerwall.com/industries/financial-services-banking/)
                  - [Healthcare](https://towerwall.com/industries/healthcare/)
                  - [BioPharma & Bio-Therapeutics](https://towerwall.com/industries/biopharma-bio-therapeutics/)
                  - [Retail](https://towerwall.com/industries/retail/)
                  - [Government](https://towerwall.com/industries/government/)
                  - [Catholic Diocese](https://towerwall.com/industries/catholic-diocese-cybersecurity/)
                  - [Cannabis](https://towerwall.com/industries/cannabis/)
                  - [Small Business](https://towerwall.com/industries/small-business/)
                  - [Enterprise](https://towerwall.com/industries/enterprise/)
          - Trends & Threats 
                  - [Remote Workforce](https://towerwall.com/trends-threats/remote-workforce/)
                  - [Vendor Questionnaire](https://towerwall.com/trends-threats/vendor-questionnaire/)
                  - [HIPAA](https://towerwall.com/trends-threats/hipaa/)
                  - [Ransomware](https://towerwall.com/trends-threats/ransomware/)
                  - [GDPR](https://towerwall.com/trends-threats/gdpr/)
                  - [Cloud Security](https://towerwall.com/trends-threats/cloud-security/)
                  - [Phishing](https://towerwall.com/trends-threats/phishing/)
                  - [Cybersecurity Insurance](https://towerwall.com/trends-threats/cybersecurity-insurance/)
- [Resources](https://towerwall.com/resources/) 
    - - Resources 
                  - Our latest insights, events,  
                     and tools to keep you safe.
          - - [Insights](https://towerwall.com/resources/?resources_category=MTU%3D&focusarea=0&industries=0&search=)
                  - [Webinars](https://towerwall.com/resources/?resources_category=MTg%3D&focusarea=0&industries=0&search=)
                  - [Whitepapers](https://towerwall.com/resources/?resources_category=MTY%3D&focusarea=0&industries=0&search=)
                  - [View All](https://towerwall.com/resources/)
- [Company](https://towerwall.com/company/) 
    - - Our Company 
                  - We are the industry’s leading cybersecurity preparedness partner.
          - - [Who We Are](https://towerwall.com/company/)
                  - [Our Team](https://towerwall.com/company/our-team/)
                  - [Our Approach](https://towerwall.com/our-approach/)
                  - [Our Values](https://towerwall.com/company/our-values/)
          - - [Awards & Recognition](https://towerwall.com/company/awards-recognition/)
                  - [Certifications & Affiliations](https://towerwall.com/company/certifications-affiliations/)
                  - [Community Involvement](https://towerwall.com/company/community-involvement/)
                  - [Careers](https://towerwall.com/company/careers/)
                  - [Contact Us](https://towerwall.com/company/contact-us/)

Topics  Center for Internet Security (CIS), private sector, Wireless Access Control, human error encryption, public sector, authentication, cannabis, cybersecurity, Enterprise

# 3 Ways to Protect Data and Control Access to It

[By Michelle Drolet](https://blog.towerwall.com/author/towerwall2020)

[Read More](https://blog.towerwall.com/author/towerwall2020)

 3 Minute Read

May 23, 2016

## Your company's data is its crown jewels, and you must protect it all times. CIS Controls 13, 14 and 15 will help you.

Earlier we delved into [disaster recovery and network security](http://www.networkworld.com/article/3035146/security/create-a-data-recovery-plan-and-secure-your-network.html). Now it’s time to take a look at Critical Security Controls 13, 14 and 15, which cover data protection and access control. The Critical Security Controls are best practices devised by the Center for Internet Security (CIS), a nonprofit dedicated to improving cybersecurity in the public and private sectors.  
 A company’s data is its crown jewels, and because it’s valuable, there will always be people looking to get their hands on it. Threats include corporate espionage, cybercriminals, disgruntled employees and plain old human error. Fortunately, it’s relatively easy to reduce your potential exposure. It calls for protecting your data, using encryption and authentication, and carefully restricting access.

### Critical Control 13: Data Protection

Do you know where your data is? A [Voltage Security survey](http://www.informationsecuritybuzz.com/overcoming-data-residency-issues/) of nearly 300 IT professionals found that 48 percent didn't even know which countries their data resided in once uploaded. Using cloud services and offering mobile device access is the norm now, and it delivers many business benefits, but we must take care to limit and audit data flow.  
 The most obvious first step is to encrypt your data at all times—in transit and at rest. Use popular cryptographic algorithms and evaluate on an annual basis to ensure your protection is still strong. You can refer to the [National Institute of Standards and Technology](http://csrc.nist.gov/projects/crypto.html) (NIST) for recommendations and further information. If properly encrypted, even compromised data will be inaccessible to attackers.

Identify sensitive data, and take steps to ensure it’s always encrypted. Use monitoring tools to expose suspicious activity and unauthorized attempts to access data, and flag them. Do regular scans to ensure that no plaintext data is on your systems. Prevent write access, block file transfer websites and be vigilant for rogue connections.

### Critical Control 14: Controlled Access Based on the Need to Know

Far too many companies don’t distinguish between sensitive data and publicly accessible information. If attackers gain entry through a weak link, then they essentially have the keys to the kingdom. Of 2,260 confirmed breaches, 63 percent leveraged weak, default or stolen passwords, according to Verizon’s [2016 Data Breach Investigations Report](http://www.verizonenterprise.com/verizon-insights-lab/dbir/). If you don’t restrict access to data based on who actually needs it, then you are presenting a much larger potential attack surface.  
 Divide your data into categories, and make sure sensitive data is protected and can be accessed only by authorized employees who have a legitimate reason to access it. If sensitive data must be sent across less-trusted networks, make sure it’s encrypted. Use authentication to verify the person accessing the data, and create audit logs that can be scanned for suspicious behavior. Restricting data access strictly to what’s required for each job role is essential if you want to prevent a sensitive data breach.

### Critical Control 15: Wireless Access Control

Wireless access is ubiquitous now, but the added convenience comes at a cost in terms of security. Attackers can potentially gain access without even having to gain entry to your building. It’s also alarmingly common for wireless attacks on traveling employees to result in data loss and sometimes infection that is carried back into the office. The BYOD trend has drastically increased the number of devices that could be usefully compromised from an attacker’s perspective.  
 You can clamp down on this threat by ensuring that every wireless device connected to your network has an authorized configuration and security profile. If you don’t know what the device is or who owns it, it doesn’t get access. The network should be scanned constantly to identify rogue access points or unauthorized devices and to expose attempted attacks.  
 In some cases, business hardware can be configured to block wireless access or to restrict it to authorized wireless networks only. Consider blocking the use of wireless peripherals, such as Bluetooth headsets, which can be very insecure. Always use encryption and authentication. Create separate virtual LANs for untrusted devices and make sure all traffic is filtered and audited.

### Tighten up

It will take some time to classify your data and create a hierarchy of access based on job roles, but it’s a necessary foundation for data security. It isn't enough to have a system to protect your data and restrict access; you must also continue to monitor and audit to identify weak spots and act immediately to strengthen them.  
 Don’t make it easy for attackers.

This article was recently published in [NetworkWorld.](http://www.networkworld.com/article/3067715/security/3-ways-to-protect-data-and-control-access-to-it.html)  
*Image credit: Thinkstock*

#### 3 Ways to Protect Data and Control Access to It

Back to Top

## Related Insights

### [Always be Prepared: Monitor, Analyze and Test your Security](https://blog.towerwall.com/always-prepared-monitor-analyze-test-security)

 Center for Internet Security (CIS), private sector, Wireless Access Control, human error encryption, public sector, authentication, cannabis, cybersecurity, Enterprise

### [Cybersecurity is only as strong as your weakest link—your employees](https://blog.towerwall.com/cybersecurity-strong-weakest-link-employees)

 Center for Internet Security (CIS), private sector, Wireless Access Control, human error encryption, public sector, authentication, cannabis, cybersecurity, Enterprise

[View All Insights](https://blog.towerwall.com)

×

## Talk with us now about:

#### Your security needs.

- ![Phone](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/phone-icon.svg "Phone")
  
  [Call 774.204.0700](tel:774.204.0700)
- ![Mail](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/mail-icon.svg "Mail")
  
  [Email Us](mailto:info@towerwall.com)

### The front line of cybersecurity.™

For over 23 years, Towerwall, a woman-owned business, has helped scores of companies safeguard their data and leverage their investment in IT with advanced information security technology solutions and services. Our experience in all facets of information security coupled with serving in the CIO/CISO/ISO roles provides a unique first-hand understanding of the security challenges organizations face daily.

### Connect

- <https://blog.towerwall.com/info@towerwall.com>
- <https://www.linkedin.com/company/towerwall-inc.?trk=pro_other_cmpy>
- <https://twitter.com/Towerwall>
- <https://www.facebook.com/Towerwall>

- [Career Opportunities](https://towerwall.com/company/careers/)
- [Contact Us](https://towerwall.com/company/contact-us/)

© Towerwall, Inc. and its licensees. All rights reserved [Privacy Policy](http://towerwall.com/privacy-policy/) Sitemap [Created by Howbridge](https://meethowbridge.com/)

[![Towerwall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/footer-logo.svg "Towerwall")](https://towerwall.com/)