Portable Devices Pose Growing IT Security Threat
Managers scrambling to manage flood of storage systems.
Computerworld - Fabiana Gower considered some unconventional methods to prevent data losses when portable storage devices began appearing in her companys IT environment about three years ago.
I stopped just short of Super Glue, said Gower, vice president of information systems at Martin, Fletcher, an Irving, Texas-based medical staffing firm.
I wasnt able to find a way to lock USB ports so that they are inaccessible to employees short of going to a thin-client environment, which would have meant [an investment of] hundreds of thousands of dollars, she added.

Fabiana Gower
Just this summer, the U.S. Department of Veterans Affairs issued a directive requiring that its employees, contractors and business partners use encryption or other means to protect data stored on all drives, including portable devices.
The edict follows the VAs loss of two drives over the past 15 months in incidents that exposed personal information of tens of millions of veterans and others.
In a statement to Computerworld last week, Bob Howard, CIO and assistant secretary for information and technology at the agency, said that the VA is also in the process of acquiring encrypted thumb drives and applying encryption to other devices and storage media. The process will be completed by the end of 2007, he said.
Martin, Fletcher eventually deployed PatchLink Corp.s Sanctuary Device Control software on the 150 PCs on the companys network to curb data breaches via portable storage devices, Gower said.
The software from Scottsdale, Ariz.-based PatchLink enables IT personnel to issue and manage permissions based on employee rank. It can also be used to compile detailed audit reports and to encrypt content as it travels from corporate networks to portable devices, she said.
For IT administrators, our job is not just setting up a computer for an employee to do their job. Our job is to safeguard the information of a company and make it accessible to those who need it and unavailable to those who dont, Gower said.
Businesses will struggle to keep their networks secure as long as they lack IT control over tiny storage devices connected to their systems, said Larry Ponemon, chairman of Traverse City, Mich.-based Ponemon Institute LLC.
Attackers today arent just college-aged kids sitting in their room at night trying to get into government systems. A lot of these guys are very sophisticated cybercriminals looking to take advantage of companies that dont have the best control over their network and devices, said Ponemon.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Datacenter Consolidation Best Practices Whitepaper
- The benefits of storage consolidation are being realized by companies and seen as a way to streamline many storage-driven applications. Learn why the...
- Eliminating VMware / Storage Related Performance Challenges
- How to proactively monitor the performance in a Fibre Channel SAN / vSphere environment is always a concern. Understand the importance of a...
- Cloud Environments Have Familiar Storage Challenges
- Cloud environments have many storage challenges that are familiar to data center managers, but due to their density and abstraction, the issues become...
- Eight Considerations for Evaluating Disk-Based Backup Solutions
- In the past, the movement from tape- to disk-based backup has been less compelling due to the expense of storing backup data on...
- ExaGrid Helps U.S. Federal Government Agencies Reduce Backup Windows and Improve Data Protection
- The U.S. Government has been the largest user of tape-based backup systems since the 1970s. Most agencies have begun to deploy disk storage... All Storage White Papers
- Understand Your Data: The Future of Backup and Archiving
- Archiving and Backup are the foundation of the next generation of information governance. However, commodity data protection tools and basic archives are only...
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn... All Storage Webcasts