Skip to navigation
   
Simon Bisson & Mary Branscombe's Blog

Lockdown

By Simon Bisson & Mary Branscombe in Editorial

Posted in USB, Laptop, Security, Mobile on January 22, 2009 at 11:28 pm

Permalink | Author Profile

If you work for a security company you wouldn’t normally leave your laptop and your BlackBerry with a journalist you’ve only just met when you go to fetch coffee. Feeling comfortable doing that says you’re confident in your security. Susan Callahan of Safend isn’t worried about leaving her laptop on a table, in a security tray, or anywhere. If she loses it, it’s just an inconvenience - not a security breach.

You probably know of Safend as a tool for protecting USB ports. That’s a big part of the security story today. Flash memory sticks are everywhere - they’re the new floppy disk that can carry all your information. Walking around the various memory companies at CES we found all shapes and sizes of memory stick, all united by being something that easily fits in a pocket. 1GB devices cost almost nothing, and the latest generation give you up to 64GB of storage. You’ll even find them built into Swiss Army knives.

64GB? That’s more than many laptop hard disks. It’s also more than 13 DVDs-worth of data.

With that amount of low cost storage available to all and sundry, it’s not surprising that businesses are seeing flash drives as a security risk. Two CD-ROMs worth of tax data caused one of the biggest data losses in the UK, so it’s easy to imagine just how much damage a tiny memory stick can do.

So how do you protect your data, when it can easily move onto a keyring?

We spent some time on a hot January afternoon at a Silicon Valley Starbucks with Susan, talking about how businesses can use endpoint security tools to protect their data. Securing USB sticks is just part of their story, as the Safend software lets you control exactly how you can use USB ports. You can set up policies for approved devices, and provide different levels of access for different classes of users. There are also rules for controlling just how DVD and CD writers can work, as well as tools for handling hard disk encryption.

That means that the CEO may get full access, while sales teams will only be able to read data sent to them by clients. Other teams might only be able to share data using encrypted memory sticks that are automatically encrypted as soon as they’re connected to a PC. Managing the rules is easy enough, with a central console and a single policy server that can handle up to 10,000 client devices. You can even set up geographic rules, to handle the differences between EU and US privacy requirements, or provide rules that work on specific file content or sizes. There’s even the option to set up rules based on content – so you could have rules that would allow staff to copy any document that doesn’t contain credit card numbers or any other identity information.

Data loss isn’t just about the network, and the Safend tools also help handle disk encryption (which is why the ThinkPad was safe on the cafe table). Lose a protected laptop and anyone who “acquires” it won’t be able to read the files – let alone copy them onto a CD or a flash disk.

There’s enough regulation out there to make device protection as important as your firewalls – so have you locked down your laptops yet?

–Simon (in Silicon Valley)

 

12345
Not yet rated
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by Dan Jones - January 23, 2009 on 9:22 am

Working in IT security, I’d be happy leaving my laptop or USB key (a ironkey) anywhere - safe in knowledge both the disk and USB key are encrypted - and that it self-destructs after only 5 bad password attempts. I am quite surprised some organisations havn’t caught onto the fact such defense is now quite easy (and not too expensive in bulk). I think DLP as described here is good - and better than nothing, but not the holy grail.

A proper DLP solution in my optinion needs to know what is being written to the USB media and thus be able to make sensible decisions in my opinion (ie allow everyone to write a personal photo, but not allow a corporate confidential document to be written to a unauthorised or unencrypted device. The dangers of a solution as described are that once someone needs “to write” a USB stick that policy will never be reversed, and thus you still have the accidental loss.

Security is this case in my opinion is not to stop bad people doing bad things - but to stop normal users doing stupid things unwittingly.

Trackback by Eusebio Bredy - February 9, 2012 on 3:37 am

greenpeace australia campaigns…

[…]various points where Judge Rodgers may have failed to exercise […]…

Trackback by Loretta Stetke - February 9, 2012 on 8:33 am

will smith and jada pinkett…

[…]the next news from the courts is now expected in the […]…

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

productivity Windows Server 2008 rc bug bolt deperimeterization flash drive trends insert SIM malware mobile ofcom network 2009 SMB 2 rtm Asus wes evernote pgp Tablet PC wifi Salesforce Pal task bar ports mobile network dual display Adobe social networking mysql distributed computing icons teched Beacon visualisation developer Smartbook robot 64-bit emulator Tripit monitor BBC keyboard parallel computing fonts html Previous Versions lawsuit Netscape telecoms todo list biometrics pen computing ribbon Jeff Jones consolidation screen forensics Mini-Note remove back apps BitLocker battery life verdana pixetell outlook backhaul Istanbul g-1 Web 2.0 Magny-Cours green printing development system center project Qualcomm Silverlight case Skyfire SapphireSteel business technology automation flash ipv6 dvi fault hp microsoft research national museum of computing IM phone management citrix Google Spreadsheets Vodafone natural interface culture Crossfader RSS search gabriola O'Reilly ec2 Tablet Kiosk conferences credit crunch WWW power WEI acquisitions MIX adfs control panel windows server 2008 r2 p2v enterprise architecture Treo Pro Safari data centre LiveID cloud service google online applications web2expo congestion charge data tariff Palladium networks community RSA 2008 Enterprise 2.0 Hp 2710p Active Directory encryption TechEd 2008 whitelist Fire Eagle nvision08 video Seagate images ultraportable Windows 7 vs Windows Vista ProCurve amazon utilities BES business intelligence wireless USB city IBM business installer camera toshiba Embarcadero Mark Hurd future in review radeon twitter mobile data tariffs voice recognition Palm HSPA microsoft research patent Vista smartphone IT policy optical interconnects disk space FUD cloud computing Express Gate upgrade application compatibility cloud Java NAS hard drive information cards mash-up server sprawl mms 2009 tele atlas spam fighting HTML 5 Mono wubi utility Gears WPF regulations OEM migration Wimbledon Volume Shadow Copy futura macro aws Frauenhofer Secunia colossus education user interface green IT data Toshiba Portege R500 MIX08 cracking Internet Explorer ADFS 2.0 merger OpenID moscow EEE media tablet moblin Ask.com dual boot 2.0 mobile Internet Explorer 8 office 2010 hierarchical temporal memory NGSCB greenplum SSD data loss prevention Mercury etech .NET information flex hdmi netbook infrastructure QWERTY firewall appstore Xobni ikea SKU switch calit2 safend Large Hadron Collider Reqall appzero context people system management gamer Bill Gates semiotics direct access Wyse clean install cables mobile Linux virtual desktop IT transformation Tom Hogan griffin identity theft Numenta fibre beta test business model connectivity service oriented enterprise enterprise ubuntu advertising Lenovo geocaching office network android security paradox information rights management Opteron screencam bletchley park geneva augmented reality open source drivers management logitech CTO hibernation navteq design mobile working Chrome sun i-mate Ruby Windows Mobile CUDA privacy secure anti-virus database DLP routing Motorola Eee PC mainframe media center MING politics history web vmware IO analytics desktop. PC beta Nuance troubleshooting Xen open Nokia security fingerprint hacking machine learning software CERN Girl Geek Dinners disk bugs data loss Windows Live eu goview cosmic rays private cloud Sony SP1 isp search co-processor hold music docking station designer transcoding Opsware windows bombe anti-patterns Google vulnerabilities LHC bea mscape ATI anti-trust xT9 Credentica instant messaging email Barracuda NexT user experience GPL power saving power cuts NVIDIA d2c RIA mythbusters T9 Dopplr HSDPA TSA VSSAdmin Bill Cheswick oracle Facebook CPU target setup RAZR uninstall ucsd thin client SBS benchmark IDF legacy hardware london Moonlight Visual Studio atom tennis Live Mesh Mozilla Tim Berners-Lee wave numbers MRDA demo g-2 Hugh Thompson server ballmerbot T-Mobile IT automation AskEraser WinHEC Google IO conference annotation wildfire how do I get the back off? innovation MacWorld 2008 lost server Linux ipsec it pro licensing performance mobile broadband virus spam GPU geotagging DSL phone settings Acrobat Pro AMD isps DisplayLink Quest GPS turing data centre transformation laptop police terabytes BT electricity price cisco identitity fingerprint scanner 965 october RBL quiz Bing yahoo netbooks Trampoline old software catalyst virtualisation IT value regulation codec multiple monitors webkit deborah adler MacBook Air O2 storage Verbatim social engineering iPhone accelerator HMT claims AuthenTec international roaming magic bbc iplayer RIM Dell Intel BlackBerry Internet meaning Opera accessories Trend Micro Corsair support high performance computing downturn Trolltech installation ANR processors cam geek tourism ontier Apple CES TouchSmart Gartner christmas IIW2008b EMC Firefox M&A thermo offload bandwidth exchange DOS traffic Location training Itanium UMPC Microsoft hyper-v workflow rich client CardSpace microsoft security essentials streaming media Netscan venture capital office politics Greasemoneky exabytes Tombstone Objects patch Tuesday ClipMate active digitiser applications HP iPass windows 7 maps market share display demo09 macbook Delphi Protected View cold fusion netiquette security theatre collaboration voice Clear RX amherst OFCOM Jeff Hawkins Ruby On Rails navigation gameboard ruggedized fire usb relocation cellcrypt AIR competition MAX lockdown OQO CIO timezones Windows Server no signal DOSBox gaming public cloud winhec2008 mobility Ray Ozzie identity metasystem business continuity Loki browser business technology optimisation legislation pre-boot disaster recovery HTC 3G MWC web 2.0 expo interoperability Google Sets power supply mapping
Advertisement
Advertisement