Title: Intra-Company Data Traversal
1Intra-Company Data Traversal
- Protecting Customer Data
- from Parent Company
2Intra-Company Data Traversal
Auditor Can Allstate Corp. capture outbound
traffic from Allstate Bank?
Jason Yes
I mean no!
Ah damn!
3Intra-Company Data Traversal
- The Business Need
- Allstate Bank (AB)
-
- wants to protect its customer data from
-
- Allstate Corp. (ALL)
4Intra-Company Data Traversal
- The Problem
- How do we protect non-public customer data that
is being electronically transmitted from Allstate
Bank through Allstate Corps corporate LAN?
5Intra-Company Data Traversal
- Problem Specifics
- Regulatory
- Regulations dictate that there can only be
limited access to sensitive customer information. - US Consumer Privacy laws must be followed in
all cases.
6Intra-Company Data Traversal
- Problem Specifics
- Data
- For that information that can be sent
- Data cannot be in Plaintext as it traverses
Allstate corporate network. - Payload of packet cannot be encrypted by router
when it reaches the Allstate corporate network
perimeter.
7Intra-Company Data Traversal
Solution IPSec tunnel between 2 new Cisco
routers
8Intra-Company Data Traversal
Auditor Can Allstate Corp. capture outbound
traffic from Allstate Bank?
Jason Yes
But only in 1 place instead of 5