|
|
|
|
|
by jessaustin
4928 days ago
|
|
Just to clarify: are you more concerned about the Googlebot reading your documents to sell you consumer products than you are about employees attaching business or customer data to email or shared docs? Because I'm operating with a much different threat model. Email is not and never has been secure. It is sent in plaintext unsecured from one unauthenticated mail server to the next. The moment the user attaches data to an email the game is over and we have lost. Sensitive data must be kept in systems that are designed to store sensitive data, and which do not have a "forward to my gmail account" feature. That's how IT can be relevant: provide that system. You might prompt the business to reclassify some formerly sensitive data as rubbish they're allowed to play with, but then their fingerprints will be all over the corpse. |
|