Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 12 December 2009

USBs : An Employees Dream- IT’s Worst Nightmare

Posted on 06:58 by Unknown

Define and Enforce an Effective IT Security Strategy or Risk Exposure

By John Jefferis, Vice President, Ironkey

USB drives, or memory sticks as they are sometimes referred to, are immensely popular and increasingly selected as the weapon of choice by employees looking for flexibility of their working environment. Having proved invaluable in increasing productivity they are easy to use, regardless of the user’s technical ability, and able to carry millions of pages of data. The scenarios where they bring benefits are numerous, for example working from home, working on location at a client site, those using multiple computers, when travelling they can provide a means to back up your lap top, transfer information between your portable devices, and sharing data with customers at conferences or exhibitions, to name just a few. However, a word to the wise - this productivity comes at a cost higher than the original price tag.

These dream devices are proving an absolute nightmare for IT managers as they struggle to ensure the data they carry is secure. A standard DVD-data-sized (4GB) key fob drive can be bought online for less than ten pounds and from high-street retailers for little more. Coupled with the fact that a growing number of mobile phones and MP3 players are now starting to reach this level of storage capacity - and come with standard or mini-USB connectors, and you begin to understand the scale of the problem.

One serious risk is that of being lost or stolen as highlighted in an annual national independent study conducted by Ponemon Institute into ‘Trends in Insider Compliance with Data Security Policies’. In its most recent study (published June 2009) it discovered that 43% of respondents admit to having lost or had stolen a portable data-bearing device. Another increasingly apparent issue is that of spreading viruses and malware. This was aptly illustrated by Ealing Council who revealed in September that it was forced to cut internet and phone links to preserve “core systems and data” when a worker plugged an infected memory stick into a computer in May 2009. The sophisticated virus spread rapidly, with further shutdowns required when the network was re-infected twice the next week, with all terminals having to be rebuilt or replaced. The Council is faced with a £501,000 bill for the emergency recovery and in lost revenue but it is feared the final cost could top £1.1 million if a new computer security system is needed. This is not an isolated incident and, in fact, was virtually the same as that suffered by Manchester City Council in February.

However, both of these risks can be counterbalanced by defining an effective IT security strategy. Here’s how:

Step 1: Ban Staff Using Unprotected Sticks and Uncontrolled Devices

In the first instance, companies should bar staff using vanilla (i.e. unprotected) USB sticks onto company premises, or use them on work-at-home PCs if company data is involved.

Step 2: Give Them Something They Can Use

Employees want to use them so remove the allure of vanilla sticks and provide an authorized corporate secure USB storage device. Increased productivity should compensate for the initial outlay and using a pooling system will help keep a lid on costs. By definition secure means a USB stick with a degree of security intelligence built into it. This intelligence is quite benign and sensible, typically including on-board anti-malware and virus software - updated across the Internet each time the device gains access.

Step 3: Induction

If you don't already have a staff induction course, you need one, as all sorts of company legislation needs to be explained to new employees, as well as temporary workers from agencies. An important part of the process is to familiarise all employees of security policies. It is worth stating that any amendments to the security policy, and any other policies for that matter, should be communicated to existing employees with a method for tracking those that have been made aware of the change - ignorance shouldn’t be used as a defence.

Step 4: Education versus Draconian

Rather than ‘because I said so’, all mandates should include an educational element so as not to be viewed as a pointless exercise created by those who ‘don’t understand how we work’. Explaining the reasoning behind rules will often gain employees support as they can follow the impetus behind the instruction rather than simply wishing to circumnavigate the obstruction.

Step 5: Identify What’s Out There

It's vital to use on-network/IT resource technology that analyses new devices as they are hooked up to the company system and lock out any unauthorised device. No exceptions, even for the MD.

Step 6: Manage Centrally

All devices should be involved in a remote portable device scheme, whereby portable devices are updated with IT security policies and checked for general well-being as they connect to the company IT resource - directly, or across the Internet. A reputable IT security system will include the remote management and tracking of secure intelligent flash drives, and also include the ability to recover content, reset a password and re-deploy or destroy data on a device as and when required. It's often this remote control facility that proves a serious lifesaver for staff and management, as USB sticks and portable storage devices can throw a wobbly.

Step 7: Back Up

Finally, you'd be surprised how many people rely on these devices yet fail to take a back-up - even though their desktop or laptop PC is backed up automatically and regularly.

In an ideal world, all staff would understand the need for IT security, and backups for that matter, but life’s too short, and some staff, let's face it, have other priorities in life. They - and we - are only human after all. This is where an effective IT Security Strategy that utilises automated security management of portable storage devices, as well as other on-network resources, is so critical. Good management software operates unobtrusively in the background.

We can't all be super-tech-savvy Tom Cruise in Mission Impossible, but we can use our IT resources sensibly and comply with best practice, without having to worry about it. That's what differentiates a good IT security strategy from an effective one.

Ironkey is exhibiting at Infosecurity Europe 2010, the No. 1 industry event in Europe held on 27th – 29th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

IronKey's award-winning products and services combine the world's most secure flash drive with the world's most powerful USB management software. IronKey's USB flash drives bring the power of authentication, encryption, identity management and privacy to businesses and consumers in 23 countries. IronKey's management software and associated services allow enterprises of all sizes, government agencies, the military, and other organizations to take back control of the mobile data that has been leaking out of their organizations due to the uncontrolled proliferation of USB drives.

<>

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • DDoS-Attacks disable many shopping websites, including Amazon
    Just in time for last minute Christmas shopping major shopping sites disabled by Michael Smith (Veshengro) London, December 26, 2009: An...
  • Cyber-Ark Expands RSA Secured Partner Program Certification Status
    Cyber-Ark Privileged Identity Management Suite, Inter-Business Vault and Sensitive Document Vault Now Formally Interoperable with RSA enVisi...
  • Infosecurity Adviser applauds forensics lab training facilities at key UK university
    London, UK. May 2009: Infosecurity Adviser, Infosecurity Europe’s online community for the information security industry, has published a r...
  • Scientific company discusses simultaneously protecting applications and data
    Simultaneously protecting applications and data: The next evolution in security? September 2009 (Eskenzi PR) – In a recent Imperva podcast...
  • TUFIN TECHNOLOGIES WINS the PRESTIGIOUS 2010 Computing Security Award for ‘Best bench tested solution of the Year’
    Network Computing and Computing Security Magazine Editors Select Tufin’s SecureChange Workflow as the Top Product Reviewed in 2010 Londo...
  • Brocade Service Could Help Reduce Billions in Data Centre Operations Costs
    New Energy Efficiency Review provides holistic assessment and remedial strategies to help companies optimise efficiency and reduce costs Ene...
  • Tufin survey reveals the truth about fudging audits, IT cost cutting and buying equipment online
    Ramat Gan, Israel – May 27, 2009 – Tufin Technologies today announced the results of its “Reality Bytes” security survey. The survey parti...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • ISACA’s EuroCACS Conference Demystifies the Cloud
    Event for IT Professionals Will Take Place 20-23 March, Manchester London, England, (8 th March 2011)— Global business and information ...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ►  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ►  January (27)
  • ▼  2009 (240)
    • ▼  December (25)
      • MBNA laptop fiasco could easily have been avoided
      • Networking technology set for growth
      • DDoS-Attacks disable many shopping websites, inclu...
      • Fortify Software Launches Hosted Software Security...
      • Launchpad Europe welcomes EITO predictions for ICT...
      • ISACA Launches Risk IT to Help Organizations Balan...
      • Parkeon Chooses Fortify Software To Keep Hackers A...
      • BridgeHead Software refutes suggestion that hospit...
      • Industrialisation of Hacking Will Dominate 2010
      • Mobile data problems? Switch to an encrypted hard ...
      • Hackers Claus havoc at Xmas – shows study!
      • Christmas shopping period worst time for leaving m...
      • Infosecurity Europe 2010 Hall of Fame nominations ...
      • 'EastEnders' laptop theft highlights failure to en...
      • Cloud vs conventional storage and computing in gen...
      • USBs : An Employees Dream- IT’s Worst Nightmare
      • A third of workers will Steal Data to help a frien...
      • VIRGIN MEDIA PARTNERS WITH TUFIN TECHNOLOGIES AND ...
      • DeviceLock now thwarts data leakage via iPhone and...
      • Novatel MiFi™ 2352 Intelligent Mobile Hotspot – Pr...
      • Bell introduces the award winning Novatel Wireless...
      • Recent issues with Skype shutting down
      • Royal Borough of Kensington & Chelsea Leverages Fa...
      • Serial train laptop thefts highlight need for encr...
      • A Good Samaritan
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile