Search
Search
Login
 Remember me
Sign up for free membership
Search

2010, Sep 03
RSS

  • Home
  • Security Tips
  • White Papers
  • Blogs
  • Media
  • News
  • Topics
  • RSS

 
 
Home » Tips » Procedures and Governance , Security best practices » Using PDF redaction tools with redacted document policies

Using PDF redaction tools with redacted document policies

Using PDF redaction tools with redacted document policies

Tags:   Allow Fast Saves  Microsoft Office  PDF  redaction

By Michael Cobb, Contributor | Jul 21, 2010

comments 0 comments
Facebook Facebook
LinkedIn LinkedIn
Digg Digg
email
print

I used to receive lots of questions from readers concerned about security issues with the "Allow Fast Saves" option in various Microsoft Office products. The idea behind the "Fast Save" feature was to speed up the process of saving a document or presentation by saving only the changes that were made and appending them to the original document. This meant that the saved document could contain metadata, such as comments and deleted text. Anyone could use a text editor or Word's "Recover Text" function to view the text that had been "deleted." Also when these documents were converted to another file format, such as HTML, the "deleted" text would often be included in the new document.

This and Word's "Track Changes" functionality have created some embarrassing security breaches over the years, wherein sensitive and secret information has been unwittingly disclosed to people who either weren't intended to see it or not cleared to see it. Documents that were published using Word, for example, revealed UK government doubts over controversial plans to hold terror suspects while another revealed private annotations of a list of political donors.

Similar problems of inadequate redaction -- the editing and preparation of text for publication -- are now becoming commonplace with PDF documents. Late last year, HSBC Bank USA N.A. exposed details of electronically filed bankruptcy proceedings (.pdf) involving U.S. customers by failing to properly redact the documents they published online. Earlier in the year the transcript of the closed hearing on the Facebook/ConnectU settlement did have all references to the settlement's financial terms redacted, however, the redaction wasn't performed correctly, as the sensitive information was simply covered up with white boxes. A simple copy and paste revealed the founders of ConnectU received a $65 million settlement.

As you can see, releasing electronic documents without properly preparing them for publication can cause serious breaches in data security. It's an obvious yet common way for sensitive data to leak out of an enterprise network. Not only should enterprise information security processes include a redacted document policy, but staff members also need to know how to accomplish redaction correctly. Proper electronic redaction is the complete removal of content from an electronic document, making it irretrievable and unavailable for view, print, search or copy. Redaction requires the right tools and training so the redactions are permanent.

 
 
123
This article originally appeared on SearchSecurity
comments 0 comments
Facebook Facebook
LinkedIn LinkedIn
Digg Digg
email
print

Similar

Related Articles

  • The benefits of GRC platform implementation

  • A mobile governance strategy must underpin the use of mobile technologies at work

  • Security log management 101

  • NIST thumb drive best practices

  • Managing your USB ports

Add comment

Post a Comment

The content of this field is kept private and will not be shown publicly.
Input format
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <img /> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <embed> <object> <strike> <caption>
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.

More information about formatting options

 

Similar

Related Articles

  • The benefits of GRC platform implementation

  • A mobile governance strategy must underpin the use of mobile technologies at work

  • Security log management 101

  • NIST thumb drive best practices

  • Managing your USB ports

knowledge_central_tab

 
 
Knowledge Central
  • White Papers
  • Case Studies
Cisco: Network security landscape remains vulnerable
Cisco has announced the findings for the Cisco 2010 Midyear Security Report, which highlights the rise of Spam, the lax attitude towards enforcing rules on social media use, and the potential danger of popular 'virtual farms'.
Vulnerability exploits: A game of cat and mouse
When it comes to vulnerability exploits, it's a game of cat and mouse. The faster we are at closing the vulnerability holes, the better our chances of cutting off the 'life-blood' of hackers and other cyber-criminals.
 
 
 
Catching potential data breaches before they become one
When a major federal agency faced yet another cyber attack from outside the country, it looked to the security experts at Verizon to deploy a state-of-the-art, turn key Security Operations Center (SOC).
Lakshmi Vilas Bank steps up IT security
Southern Indian bank Lakshmi Vilas has embarked on an IT security infrastructure and data center upgrading project.
 
 
 

Recent popular content

Most Read
SonicWALL releases mid-year cybercrime trends summary
Singapore businesses step up efforts in information protection
Android game spies on your location
Dangerous worm attacks instant messaging clients
Major fake anti-virus attack spreads

Search SMB Asia

  • Hosted collaboration: An affordable UC strategy for SMBs
  • Hitachi lets you tap cloud storage at your own pace
  • Increase productivity with Fujitsu's new Zero-Watt technology server
  • Adeptol's SaaS-based document viewer promises faster loading time
more




Site map
Security Asia
About Us
Print/Digital Subscription
Sales
Feedback
Security Tips
Expert Opinions
Research
White Papers
Case Studies

Blogs
Topics
Application security
Disaster recovery and business continuity
Identity management and access control
Information security careers, training and certifications
Topics
Network and Internet Security
Security best practices
Security threats
Surveillance and facilities management
Media
Videos
Podcasts
Webcasts
News
RSS

 
 
  • Home
  • About Us
  • Print/Digital Subscription
  • Sales
  • Feedback
  • Editorial Calendar
Questex Asia media brands
Telecom Asia | Enterprise Innovation | ComputerWorld Hong Kong | CFO Innovation Asia  | Networks Asia | Telecoms Europe | The Green Channel | CRM Management | eGov Asia | SMBWorld | SMB World Asia | Storage Asia | Security Asia | Asia Cloud Forum | Hospitality Architecture+Design | Hotel Management Asia | Questex Asia Events
© 2010 Questex Asia Ltd., a Questex Media Group company. All rights reserved. Reproduction in whole or in part is prohibited. Please send any technical comments or questions to our webmaster.