MTN Data Protection
Case Study
Purpose of the project
To protect individual privacy and stop data manipulation, data security is necessary. No company today, no matter how big/small, should ignore putting security measures in place. Information security plans that are inadequate can have major negative effects on businesses. Here are a few precautions to take into account:
- Maintaining company community: Routine data backups ensure business continuation in the event of data loss or inaccessibility.
- Preventing data breaches: Businesses must safeguard the transactions and records of their customers, employees, and other stakeholders. Data breaches have a number of detrimental effects on firms, including financial losses, a decline in public trust, harm to their brand, and a potential influence on future revenues.
- Blocking illegal access: As more sophisticated hacking methods are developed, hackers are growing.
The Dilemma
In 2020, a gap analysis was done in relation to the specifications of POPI within the context of MTN. There are standards that must be followed in order to deploy MTN security safeguards. MTN needed the help of a managed service provider, which will play a crucial role in MTN’s security infrastructure by giving MTN security a consolidated view of data protection. Data protection ensures that data is not harmed, is only accessible for legitimate purposes, and conforms with all applicable legal and regulatory requirements. Protected information must be used for the intended purpose and be available when needed. Data in three states are the main focus of MTN data protection:
- Data at rest is defined as information that is kept on a physical or logical medium but is not being accessed. Examples include documents on hard drives, file servers, databases, flash drives, and other storage devices.
- Data in transit – Information that is transferred across a private or public communication channel, like email, the web, Slack or Microsoft Teams for collaborative work. It is information that is moving between locations.
- Data in use – When data is opened by one or more programs for processing, consumption, or user access.
Project Goals
The responsibility for ensuring a comprehensive managed service for the Data Protection Portfolio, which entails Privacy, DLP, Database monitoring, data encryption, and data masking, falls to Providence Software Solutions.
- Administer Data Privacy Services and DLP Services
- Monitoring managed database activity
- Regular operational actions brought about by DLP infractions
- Improve data security across MTN by documenting protocols and procedures for data protection
- Create and keep an inventory of important data repositories
- Answer to end-user questions about violations of DLP regulations on a daily basis
- Compiling reports and making recommendations for potential future policy options after analyzing DLP violation data
- Coordinating on the findings of the DLP violations-related responsibilities with the MTN security team
- Put security tools and procedures in place to ensure that all data is protected
- Provide integrated data protection security reports (Weekly, Monthly, and Quarterly) and give it to highlight remediation activities
- Coordinating with the Privacy office to make sure all POPIA rules are followed
The Solution
It’s crucial to correctly identify and safeguard all sensitive data you keep in the cloud when your organization moves content there. Office 365 DLP can be a helpful starting point. Consider boosting DLP efficacy with third-party solution that offers more precise and automatic classification capabilities as your information governance program develops.
DLP solutions will help MTN comply with the GDPR and the POPI Act by being implemented. Providence has the necessary knowledge, tools, and solutions to help MTN in this area.