172 karma · joined November 2, 2016
One of the primary screens in Palantir is a simple search page designed to work (and look) like Google, to search upon your entire database however you'd like. You can enhance the search function via the various attributes built into your installation or using advanced search tools. So I guess a "fishing expedition" in the traditional sense is very easy, as it's limited by the data you have, not the system itself.
The Boy Scouts of America, for example, meet criteria 1, but don't meet criteria 2 or 3 (I hope), so are therefore not a gang.
Alternatively, a person who associates with a known criminal gang and commits a violent robbery in order to obtain food for their kids, would not have their actions treated as gang-related crime because the act was not made in furtherance of the gang, but rather in furtherance of their person. If the same act was committed as a gang initiation, than it could be considered as gang-related crime.
A traditional Frat does not meet the criteria, in my mind, because there is insufficient evidence that they are committing violent acts in furtherance of the organization rather than for their own personal gain. You would have to argue that assaulting women is specifically perpetuated as part of that particular Frat's culture (not just Frats in general), and that members knowingly commit sexual assault in order share in or improve upon that Frat's culture and it's success.
I would also argue that a sub-group of wrong-doers who are part of a larger group of non-wrong-doers does not inherently define a gang. A group of bad cops doing bad things isn't inherently a gang, nor does it make cops a gang. A better example would be the CRASH cops from Rampart who essentially created distinct group within the police department, with names and symbols, who committed a variety of violent and non-violent crime in furtherance of the group itself, not the individuals or the police in general.
1. Data tagging or classification - identify and tag your sensitive data, then use the tags to control/monitor what happens to it. If done fully and correctly, you only have to worry about the data that matters, not someone's chili recipe or their kid's soccer schedule. The industry term is Crown Jewels, which represents the data that is absolutely critical to your success and would be catastrophic if lost. Secure your CJ, and your biggest risk is mitigated.
2. Egress monitoring - establish tools or processes to monitor what data is leaving your company, where it is going, and how it is getting there. Look for anomalies, abuses, and undesired activities. Perhaps your intellectual property should never be in China.. uploads to 163.com or message attachments to QQ messenger addresses might be concerning.
3. Technical controls - Does your company need USB drive access? If not, block them all from moving data via USB. Does anyone in your organization burn data to CD/DVD media? No? Block it. Turn off the egress vectors that aren't needed at a user/team/site/org level. The most common egress vectors are USB, CD/DVD, Email, Network Upload, Print, and wireless transfer like bluetooth. There are others, but these are the most encompassing. You can do things like block all emails going to personal email domains like gmail or yahoo; limit print amounts to 20 pages per user per day; or block access to all domains/IP's in specific countries or regions on the network.
4. Security Awareness - Employees need to be fully informed about the data protection requirements you have in place, and the related consequences for breaking acceptable use policies. Education and awareness campaigns are key, and probably the most overlooked option available. I personally believe informing employees about real life cases of data loss/theft, whether they are your own or just in your industry, is crucial in making the risk seem more real.
I can't recommend any specific products, but in general I would say look for tools that can give you things like: data tagging, network activity logging, end-point monitoring, anomaly detection, live response, data loss prevention solutions, and/or critical data protection.