Industry


Ads by TechWords

See your link here


So, encrypt already

In recent days, the Transportation Security Administration (TSA), Home Depot and Administaff have managed to join an ignominious list of organizations that have lost laptops containing sensitive and personally identifiable information.

None of them apparently had encrypted their data to protect against a breach in the event the systems were lost or stolen. This year alone, there have been more than 60 separate incidents involving potential data compromises resulting from lost or stolen laptops and desktop computers, according to the Privacy Rights Clearinghouse (PRC), which maintains a chronological list of data breaches starting around the ChoicePoint incident (remember that?) in 2005. That number represents more than 20% of the 270 or so disclosed data breaches listed on the PRC web site since January this year.

According to most security analysts I speak to, it's baffling really why none of these organizations thought about encrypting the data on these systems before the incidents happened. The analysts are baffled. I'm baffled. What part of encryption don't companies get? From what I can gather, data encryption these days is a fairly straightforward thing to do and not quite as hard to manage as it was a few years ago. There are any number of vendors in the market offering everything from whole disk encryption to file, folder and field-level encryption capabilities -- all of which can be implemented without the user having to do anything about it or even knowing about it.

Sure there's a cost, especially for large organizations with tens of thousands of systems that may need to be protected. But, say the analysts, it's far better to invest in prevention than to spend a whole lot more on clean-up. It's that whole "ounce of prevention" thing. Sage advice.

So why is it that so many organizations have still not implemented encryption, at least on their laptops and other mobile devices? Laptop losses aren't exactly rare. And it's not like companies have much choice left any longer anyway. Industry standards such as the Payment Card Industry data security standard and rules in several states explicitly require companies to use encryption for protecting data.

I'm willing to bet anything that each of the organizations that suffered data compromises from lost laptops and desktops had antivirus tools and firewalls and anti-spyware tools protecting the data. These tools are a given now. It's the basic cost of entry, if you will, to own a laptop or any device that connects to the Internet. But such tools don't buy any protection against system loss or theft. So isn't it well past time to start thinking of encryption in the same way that companies think about anti-virus and other desktop protection tools and just implement it already? To paraphrase the old Nike shoe ad: Just do it.

What People Are Saying

These folks need to read

These folks need to read "I.T. Wars: Managing the Business-Technology Weave in the New Millennium." It's the best, leading-edge, voice for preventing business exposures and liabilities in the face of rapidly expanding technology... your people will thank you for making this book required reading at your organization.

Theres just no

Theres just no accountability where these issues are concerned. Its just easier not to.

Let's face it, the problem

Let's face it, the problem is the users, not the technology. Give a monkey a stick and their just as libel to poke their eye out as they are to dig a grub out of the ground...

"My 5gigs of super important data is in an encrypted volume and I've forgotten my password... can't you just decrypt it like they do on CSI?!?"

Um, no... sorry, I left my 512 qbit quantum computer at home...

All kidding aside, as important as encryption is, what is equally important is clear rules about where data is stored. Things like databases full of SSN numbers shouldn't be stored on a laptop, period.

On many corp laptops, the

On many corp laptops, the really important thing is cached email, i.e. Outlook, etc. Is a 500MB encrypted mail store really workable, performance wise? Better a small fusion device, set to go off after 5 bad passwords. No laptop! No problem! Well, admittedly perhaps some Edward Tellerish collateral damage....

Sure, there is on demand

Sure, there is on demand encryption in XP....but when was the last time you ran an on-demand virus scan..every time you updated any file on your system?

yup...never.

Whole disk encryption is the key for these places, or better yet...proper policies better enforced, such as not storing sensitive data on the local machines.

More importantly, if you think you built the wall no one can get in...you're an idiot. Its all a matter or prolonging the incident.

There really isn't a "cost"

There really isn't a "cost" associated with encryption...

Windows XP Professional... Right click on a folder... Properties... Advanced... Encrypt.

OMG that was hard!

That combined with reasonably strong passwords are enough to keep all but the most dedicated crackers out.

Compusec is FREE, even for

Compusec is FREE, even for professional use ... geeze ... I encrypt my personal laptop

http://www.ce-infosys.com/english/downloads/free_compusec/index.html