SlideShare a Scribd company logo
How to ensure SOX, HIPAA,
& GDPR compliance
in Dev and Test
Your Presenter
Chris.Unwin@red-gate.com
Chris Unwin
Data Privacy Specialist
DBAle on Spotify and iTunes
/in/christopherunwincambridge/
How to ensure SOX, HIPAA, & GDPR Compliance in Dev and Test
• Privilege misuse: 12%
• Hacking: 48%
• (Healthcare) Internal: 56%
• (Finance) External: 92%
• No. 1 asset involved: Database
Sources of breaches
*Study from 2018 Data Breach Investigations Report- Verizon
Privacy regulations around the world
such as HIPAA, SOX, GDPR,
CCPA, SHIELD etc. demand
effective and repeatable processes
for protecting sensitive data.
Or… Data Protection by Design and by Default.
• HIPAA: Up to$1.5m & 10 years in prison
• SOX: Up to$5m & 20 years in prison
• GDPR: Up to €20m or 4% of annual global turnover
• POPI: Up to R10 million & 12 months in prison
• PIPEDA: Up to $100,000
Cost of non compliance
Most Organizations do ‘copy-down’ Live Data
How can we stay compliant AND use
production-like data?
A small attack surface makes compliance
easier
• PII in all environments
• Higher risk
1TB
QA
1TB
Test
1TB
Dev
1TB
Prod
• PII only in PROD
• Lower risk
0TB
QA
0TB
Test
0TB
Dev
1TB
Prod
Vs
SQL Provision In Action
Case study
• Masked PHI without jeopardizing
data integrity
• Supply realistic data for testing
• New off-shore development team
HIPAA compliant
• Saving 15-20 hours a week in
provisioning processes
• Reclaimed terabytes of disk space
Benefits – recap
Q&A Session
Next steps
• Speak to us: SQLProvision@red-gate.com
• Learn more: red-gate.com/sql-provision

More Related Content

PPTX
GDPR Part 1: Quick Facts
PPTX
Security v. Privacy: the great debate
PDF
GDPR Webinar - feb
PPTX
David doughty presentation 181119
PDF
The Trick to Passing Your Next Compliance Audit
PDF
Better to Ask Permission? Best Practices for Privacy and Security
PDF
Cyber and Data Risks
PPSX
Baretzky & Associates Presentation.
GDPR Part 1: Quick Facts
Security v. Privacy: the great debate
GDPR Webinar - feb
David doughty presentation 181119
The Trick to Passing Your Next Compliance Audit
Better to Ask Permission? Best Practices for Privacy and Security
Cyber and Data Risks
Baretzky & Associates Presentation.

What's hot (16)

PDF
Your data is showing
PPTX
Privacy Discusssion GM667 Saint Mary's University of MN
PPTX
GDPR How ready are you? The What, Why and How.
PDF
Seattle Tech4Good meetup: Data Security and Privacy
PDF
Logikcull Webinar: Preventing the #1 Litigation Risk
PPTX
Online privacy & security
PPTX
Cyber threat trends
PDF
Improve Cybersecurity Education Or Awareness Training
PDF
PIPL - Steady Growth & Asset Monetization
PPTX
Privacy: Protecting Personal Information
PPTX
Justin Harvey - Apple vs DOJ: Privacy in Today's Enterprise
PDF
Security, Privacy Data Protection and Perspectives to Counter Cybercrime 0409...
PDF
How to Response Cyber Data Breaches at Pakistan
PDF
Real World Cybersecurity Tips You Can Use to Protect Your Clients, Your Firm,...
PPTX
Ensuring GDPR Compliance - A Zymplify Guide
PDF
7 Key GDPR Requirements & the Role of Data Governance
Your data is showing
Privacy Discusssion GM667 Saint Mary's University of MN
GDPR How ready are you? The What, Why and How.
Seattle Tech4Good meetup: Data Security and Privacy
Logikcull Webinar: Preventing the #1 Litigation Risk
Online privacy & security
Cyber threat trends
Improve Cybersecurity Education Or Awareness Training
PIPL - Steady Growth & Asset Monetization
Privacy: Protecting Personal Information
Justin Harvey - Apple vs DOJ: Privacy in Today's Enterprise
Security, Privacy Data Protection and Perspectives to Counter Cybercrime 0409...
How to Response Cyber Data Breaches at Pakistan
Real World Cybersecurity Tips You Can Use to Protect Your Clients, Your Firm,...
Ensuring GDPR Compliance - A Zymplify Guide
7 Key GDPR Requirements & the Role of Data Governance
Ad

Similar to How to ensure SOX, HIPAA, & GDPR Compliance in Dev and Test (20)

PDF
Don't think DevOps think Compliant Database DevOps
PDF
DBAs - Is Your Company’s Personal and Sensitive Data Safe?
PDF
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
PPTX
BSI: Compliance and the Art of Possible
PPTX
GDPRBrief.pptx
PDF
Data- and database security & GDPR: end-to-end offer
PPTX
GDPR in the Healthcare Industry
PDF
PCI DSS Compliance in India .
PDF
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf
PPTX
The EU General Protection Regulation and how Oracle can help
PDF
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
PPTX
Data protection and privacy in the world of database DevOps
PPTX
GDPR: 20 Million Reasons to get ready - Part 1: Preparing for compliance
PDF
Mastering Data Compliance in a Dynamic Business Landscape
PPTX
Microsoft dynamics 365 for small and medium sized charities - session 2 gdpr
PDF
Maintaining Data Privacy with Ashish Kirtikar
PDF
How to implement gdpr in your document repository
PDF
GDPR - Sink or Swim
PDF
Setting the right GDPR priorities
PPTX
Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business
Don't think DevOps think Compliant Database DevOps
DBAs - Is Your Company’s Personal and Sensitive Data Safe?
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
BSI: Compliance and the Art of Possible
GDPRBrief.pptx
Data- and database security & GDPR: end-to-end offer
GDPR in the Healthcare Industry
PCI DSS Compliance in India .
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf
The EU General Protection Regulation and how Oracle can help
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
Data protection and privacy in the world of database DevOps
GDPR: 20 Million Reasons to get ready - Part 1: Preparing for compliance
Mastering Data Compliance in a Dynamic Business Landscape
Microsoft dynamics 365 for small and medium sized charities - session 2 gdpr
Maintaining Data Privacy with Ashish Kirtikar
How to implement gdpr in your document repository
GDPR - Sink or Swim
Setting the right GDPR priorities
Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business
Ad

More from Red Gate Software (20)

PDF
The future of DevOps: fully left-shifted deployments with version control and...
PDF
Embracing DevOps through database migrations with Flyway
PPTX
Database DevOps for Managed Service Providers
PDF
Mizuho Financial: Launching our Database DevOps journey
PDF
7 steps to effective SQL Server monitoring
PDF
Level up your deployments for SQL Source Control
PDF
Key findings from the 2020 state of database dev ops report
PPTX
Extend DevOps to Your SQL Server Databases
PDF
2019 year in review slides
PPTX
What we learned at PASS Summit in 2019
PPTX
Quality in Software Development: Anglia Ruskin University
PPTX
How SQL Change Automation helps you deliver value faster
PPTX
DevOps essentials from Abel Wang and Steve Jones
PPTX
Successfully migrating existing databases to Azure
PPTX
The Ultimate Guide to Choosing and Implementing the Right Monitoring Tool
PDF
Everything You Need to Know About the 2019 DORA Accelerate State of DevOps Re...
PDF
Using Redgate, AKS and Azure to bring DevOps to your database
PDF
Using Redgate, AKS and Azure to bring DevOps to your Database
PDF
How to Pitch a Software Development Initiative and Ignite Culture Change
PDF
Taming the Wild West
The future of DevOps: fully left-shifted deployments with version control and...
Embracing DevOps through database migrations with Flyway
Database DevOps for Managed Service Providers
Mizuho Financial: Launching our Database DevOps journey
7 steps to effective SQL Server monitoring
Level up your deployments for SQL Source Control
Key findings from the 2020 state of database dev ops report
Extend DevOps to Your SQL Server Databases
2019 year in review slides
What we learned at PASS Summit in 2019
Quality in Software Development: Anglia Ruskin University
How SQL Change Automation helps you deliver value faster
DevOps essentials from Abel Wang and Steve Jones
Successfully migrating existing databases to Azure
The Ultimate Guide to Choosing and Implementing the Right Monitoring Tool
Everything You Need to Know About the 2019 DORA Accelerate State of DevOps Re...
Using Redgate, AKS and Azure to bring DevOps to your database
Using Redgate, AKS and Azure to bring DevOps to your Database
How to Pitch a Software Development Initiative and Ignite Culture Change
Taming the Wild West

Recently uploaded (20)

PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
PDF
System and Network Administration Chapter 2
PDF
Digital Strategies for Manufacturing Companies
PDF
Softaken Excel to vCard Converter Software.pdf
PPTX
Odoo POS Development Services by CandidRoot Solutions
PDF
PTS Company Brochure 2025 (1).pdf.......
PDF
Cost to Outsource Software Development in 2025
PDF
Upgrade and Innovation Strategies for SAP ERP Customers
PDF
medical staffing services at VALiNTRY
PDF
Digital Systems & Binary Numbers (comprehensive )
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PPTX
Computer Software and OS of computer science of grade 11.pptx
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
iTop VPN Free 5.6.0.5262 Crack latest version 2025
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PPTX
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PPTX
assetexplorer- product-overview - presentation
PDF
Odoo Companies in India – Driving Business Transformation.pdf
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
System and Network Administration Chapter 2
Digital Strategies for Manufacturing Companies
Softaken Excel to vCard Converter Software.pdf
Odoo POS Development Services by CandidRoot Solutions
PTS Company Brochure 2025 (1).pdf.......
Cost to Outsource Software Development in 2025
Upgrade and Innovation Strategies for SAP ERP Customers
medical staffing services at VALiNTRY
Digital Systems & Binary Numbers (comprehensive )
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Computer Software and OS of computer science of grade 11.pptx
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
iTop VPN Free 5.6.0.5262 Crack latest version 2025
Wondershare Filmora 15 Crack With Activation Key [2025
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
wealthsignaloriginal-com-DS-text-... (1).pdf
assetexplorer- product-overview - presentation
Odoo Companies in India – Driving Business Transformation.pdf

How to ensure SOX, HIPAA, & GDPR Compliance in Dev and Test

  • 1. How to ensure SOX, HIPAA, & GDPR compliance in Dev and Test
  • 2. Your Presenter Chris.Unwin@red-gate.com Chris Unwin Data Privacy Specialist DBAle on Spotify and iTunes /in/christopherunwincambridge/
  • 4. • Privilege misuse: 12% • Hacking: 48% • (Healthcare) Internal: 56% • (Finance) External: 92% • No. 1 asset involved: Database Sources of breaches *Study from 2018 Data Breach Investigations Report- Verizon
  • 5. Privacy regulations around the world such as HIPAA, SOX, GDPR, CCPA, SHIELD etc. demand effective and repeatable processes for protecting sensitive data. Or… Data Protection by Design and by Default.
  • 6. • HIPAA: Up to$1.5m & 10 years in prison • SOX: Up to$5m & 20 years in prison • GDPR: Up to €20m or 4% of annual global turnover • POPI: Up to R10 million & 12 months in prison • PIPEDA: Up to $100,000 Cost of non compliance
  • 7. Most Organizations do ‘copy-down’ Live Data
  • 8. How can we stay compliant AND use production-like data?
  • 9. A small attack surface makes compliance easier • PII in all environments • Higher risk 1TB QA 1TB Test 1TB Dev 1TB Prod • PII only in PROD • Lower risk 0TB QA 0TB Test 0TB Dev 1TB Prod Vs
  • 11. Case study • Masked PHI without jeopardizing data integrity • Supply realistic data for testing • New off-shore development team HIPAA compliant • Saving 15-20 hours a week in provisioning processes • Reclaimed terabytes of disk space
  • 14. Next steps • Speak to us: SQLProvision@red-gate.com • Learn more: red-gate.com/sql-provision