Home > Data Storage Tips > Data storage management > Tools for securing mobile drives
Storage UK Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

DATA STORAGE MANAGEMENT

Tools for securing mobile drives


Kevin Beaver, CISSP
01.23.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


What problem you will learn from this tip: Information security expert Kevin Beaver outlines various security tools available for keeping your mobile devices secure when they're lost or stolen, as well as when a user loses data that has to be restored.

We hear a lot about the security risks associated with mobile drives -- such as laptop hard drives and USB drives -- and there's certainly no lack of written policies on the subject. But how can you turn your words into actions and actually make your mobile drives secure?

The first essential element for protecting information on mobile drives and setting your users up for success is to setup encryption. Yep -- the tried and true security "solution" that has failed us so many times in the past actually works very well in this situation. By encryption, I'm referring to encrypting whole disks and/or volumes -- that is, entire C: drives or entire USB drives, for example. This offers the ultimate in security. Once the lost or stolen system is powered off, hibernated or (as in the case of PDAs and smartphones) has been idle for a certain period of time, the person who found (or stole) the system will be stuck at a login prompt. Just what the doctor ordered.

There is another popular way to go about encrypting sensitive information on mobile drives. You can encrypt certain portions of your mobile drives by creating encrypted "partitions" -- something that has worked well for me in the past. However, security is much weaker here because you're depending on your users to store all sensitive information on that partition -- a major no-no.

As if user carelessness is not enough, operating systems and applications often save (and don't clean up) files in areas such as temp directories and application directories, leaving the information exposed. If a mobile device is lost or stolen, the chances are good that someone can gain access to sensitive information strewn across the drive. Therefore, whole drive encryption is the best way to go.

There are various products available to help you with encrypting your mobile drives. My favorite is PGP Corp.'s relatively new Whole Disk Encryption, which has worked flawlessly for me thus far. I encourage you to check out the other options as well, such as Utimaco Safeware AG's SafeGuard Easy and GuardianEdge Technology's Encryption Plus Hard Disk. Seagate is even offering Full Disk Encryption (FDE) technology on their notebook drives which encrypts information at the hardware level. Pretty nifty.

((Content component not found.)) There are also vendor-supplied encryption products such as Microsoft Windows' Encrypting File System, but I'm not a big fan. For starters, you must rely on your users to store all sensitive information in their encrypted folders. There are also known technology weaknesses, configuration and administration complexities, and for the truly paranoid, there's the trust factor associated with vendor-supplied encryption products. Having said this, if you're a Windows shop, you'll be pleased to know that Microsoft is including a volume encryption technology called BitLocker in the forthcoming Windows Vista…certainly worth considering when it comes out.

The second essential element for keeping your data intact is to ensure you've got good backups. A tried and true method for backing up mobile drives is to integrate your backups into an existing backup system (i.e., tape) by installing client backup software, performing an initial full backup and then performing ongoing full backups once a month or so and incremental or differential backups once a week, or whatever works best.

A product that I like even better is to implement a disk-to-disk backup product such as Acronis Inc.'s True Image Corporate Workstation. Given the low price of hard drive storage combined with Gigabit Ethernet and the ability to run while Windows is loaded makes drive backups much less painful and inconvenient. In addition, you get a great benefit on the back-end because you can "mount" the backup images as a local drive to retrieve a lost file or directory and can even restore the entire drive image to a known good state.

While you're tuned into the subject of securing down your mobile drives, don't forget about your PDAs and smartphones as they often house sensitive information your organization might not be able to afford to lose either. Companies such as PDA Defense and Pointsec Mobile Technologies offer dependable products. There's also an open source product called Keyring for Palm OS. Encourage your users to sync their devices on a consistent basis as well in the event of lost data. Also, you may wish to look past laptops and other mobile devices and consider encrypting the hard drives of desktops and servers that house sensitive information if there's any chance of physical theft.

Furthermore, the last thing you and your team need to be working on is managing cumbersome backup jobs, restoring individual files from tape and other time-wasting tasks.

For more information:

Effective storage security policies


About the author: Kevin Beaver is an independent information security consultant, author, and speaker with Atlanta-based Principle Logic, LLC. He has more than 18 years of experience in IT and specializes in performing information security assessments. Kevin has written five books including Hacking For Dummies (Wiley), Hacking Wireless Networks For Dummies, and The Practical Guide to HIPAA Privacy and Security Compliance (Auerbach). He can be reached at kbeaver@principlelogic.com.


Rate this Tip
To rate tips, you must be a member of SearchStorage.co.UK.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Data storage management
Server virtualisation may have big disaster recovery payoff
How to mitigate the performance penalties of data encryption software
Avoiding storage-related bottlenecks in virtualized environments
How to resolve storage issues in virtualized server environments
How to choose an e-discovery tool
Ten reasons storage security is critical
How to reduce risk with storage security policies
How to increase your storage energy efficiency
Why you should perform data classification
What to expect from a storage audit

Secure data storage
CommVault, McAfee partner to integrate storage and security management solution
Storage news in brief
Notes from SNW: Encryption shifts to disk drives
8 steps to better data security
Policy and technology: the belt and braces of data protection
Iron Mountain digitizes documents to bolster security
Disclosure becomes a fact of life in leaky Britain
nCipher grabs NeoScale for $1.9M
How to mitigate the performance penalties of data encryption software
Users: Storage security becoming a priority

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts