Computerworld - With more than one in three users on laptops, securing mobile devices --- and the data on them -- is becoming more critical than ever. While IT can reimage a new laptop when a unit is lost or stolen, the challenge is protecting data on the missing system -- and getting it back. The major laptop vendors all offer a range of security features and options. Here are some to consider:
Authentication
Smart cards and biometric fingerprint readers can provide two-factor authentication for system access. Some laptop models, such as Lenovo's ThinkPad X series, can store passwords on a Trusted Platform Module (TPM) chip, rather than on the hard disk drive where it might be compromised.
Biometric readers have one advantage: Users never forget to bring their fingers. On the downside, biometrics have a false-rejection rate of about one in 20, says a Lenovo representative. Dell doesn't offer a biometric reader but says 20% of its enterprise notebooks have a smart card option.
Theft recovery
A stolen laptop may have sensitive data as well as data the user created since the last backup. A tracking service such as Absolute Software Corp.'s Computrace can allow remote retrieval of critical data and issue a command to erase the disk, assuming that the missing unit attaches to the Internet and the agent software can check in. Lenovo embeds the stealth Computrace client in the BIOS in its ThinkPad X series to ensure that the client can't be removed.
Encryption
Authentication schemes won't protect laptop data if the disk is removed from the system. Windows file encryption isn't sufficient, since the user log-on unencrypts the data. Other software-based disk-encryption products can be set to encrypt only specific folders, such as My Documents, or the entire disk (which can slow performance) if you'd rather not trust users to put all of their sensitive files in the right location.
Credant Technologies Inc. in Addison, Texas, offers a third option: Its Mobile Guardian can be set to encrypt specific file types, no matter where they're stored on the disk.
One potential weakness with software-based encryption is that the key may be stored on the disk. Other products can store the key in a laptop's TPM chip, which is more secure.
Encryption features could soon be integrated into the disk drive itself. Seagate Technology LLC plans to support hardware-based disk encryption in its Momentus drives later this year. The drives could be in notebooks from major manufacturers next year. Dell and IBM have recently expressed interest in theproduct for their laptops.
Read more about Hardware in Computerworld's Hardware Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts