Ads by TechWords

See your link here
Receive the latest technology news and information.
Storage
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Portable Devices Pose Growing IT Security Threat

Managers scrambling to manage flood of storage systems.

August 20, 2007 12:00 PM ET

Computerworld - Fabiana Gower considered some unconventional methods to prevent data losses when portable storage devices began appearing in her companys IT environment about three years ago.

I stopped just short of Super Glue, said Gower, vice president of information systems at Martin, Fletcher, an Irving, Texas-based medical staffing firm.

I wasnt able to find a way to lock USB ports so that they are inaccessible to employees short of going to a thin-client environment, which would have meant [an investment of] hundreds of thousands of dollars, she added.

Fabiana Gower
Fabiana Gower
Increasing numbers of IT and security managers are facing similar pressures to control access to corporate information stored on portable storage devices that are used both with and without the blessing of IT managers, according to experts.

Just this summer, the U.S. Department of Veterans Affairs issued a directive requiring that its employees, contractors and business partners use encryption or other means to protect data stored on all drives, including portable devices.

The edict follows the VAs loss of two drives over the past 15 months in incidents that exposed personal information of tens of millions of veterans and others.

In a statement to Computerworld last week, Bob Howard, CIO and assistant secretary for information and technology at the agency, said that the VA is also in the process of acquiring encrypted thumb drives and applying encryption to other devices and storage media. The process will be completed by the end of 2007, he said.

Martin, Fletcher eventually deployed PatchLink Corp.s Sanctuary Device Control software on the 150 PCs on the companys network to curb data breaches via portable storage devices, Gower said.

The software from Scottsdale, Ariz.-based PatchLink enables IT personnel to issue and manage permissions based on employee rank. It can also be used to compile detailed audit reports and to encrypt content as it travels from corporate networks to portable devices, she said.

For IT administrators, our job is not just setting up a computer for an employee to do their job. Our job is to safeguard the information of a company and make it accessible to those who need it and unavailable to those who dont, Gower said.

Businesses will struggle to keep their networks secure as long as they lack IT control over tiny storage devices connected to their systems, said Larry Ponemon, chairman of Traverse City, Mich.-based Ponemon Institute LLC.

Attackers today arent just college-aged kids sitting in their room at night trying to get into government systems. A lot of these guys are very sophisticated cybercriminals looking to take advantage of companies that dont have the best control over their network and devices, said Ponemon.


Jump to comments

portable storage

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Data Protection is not an insurance policy -you cannot buy-back lost data
Find out why you need to maintain access to critical information to run your business and remain competitive.

Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!

5 Architecture Issues that Impact BES performance
Register to attend this LIVE Webinar to learn 5 Architecture Issues that Impact BES performance!

The Power/Density Paradox: The Result of High Density without Power Efficiency
Download this brief to explore what the power/density paradox is and how IT professionals can mitigate the risk.  

Four Principles for Reducing Storage TCO
View cost reduction strategies in this video! Provided by Hitachi Data Systems.