Home > Financial Services Information Security News > Using full disk encryption in the battle against laptop data theft
Financial Services Information Security News:
EMAIL THIS
QUESTION & ANSWER

Using full disk encryption in the battle against laptop data theft

By Editorial staff
17 Jul 2008 | SearchFinancialSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

With more employees taking their work outside of the office, data loss from lost or stolen laptops is becoming more common. In this Q&A, Michael Cobb explains whether that means it's time for full disk encryption.

Given that so much important information is found on company laptops, should a computer's entire hard drive be encrypted? What are the pros and cons?

Michael Cobb: Stories of lost or stolen laptops containing sensitive information from appear almost weekly in the news. I would consider controlling what data can be downloaded to a company laptop in the first place, but statistics certainly support more widespread use of data or hard drive encryption.

More on encryption
Laptop encryption options

Case Study: Allstate Insurance Company's Local Data Protection Project
So why don't we encrypt our data as a matter of course? Well it's probably because of the impact on performance, plus the required increase in system administration and user support. Full disk encryption (FDE) is a process that encrypts everything on a disk without user action. This includes the operating system, swap file and any temporary files. These last two can often leak important confidential data to a hacker. FDE also provides support for pre-boot authentication. It's an effective technique, but encryption can double data access times, particularly when virtual memory is being heavily accessed.

Another, more significant problem, though, is encryption key and password management. Any encryption system is only as safe as the encryption keys. With FDE, only one key is used to encrypt the entire disk. Usually keys are stored on the local system, and their sole protection is typically the user's password or passphrase. And we all know how weak they can be! Disk encryption therefore requires policies that enforce strong passwords and can handle forgotten passwords, encryption key backup processes and employee termination.

Despite these disadvantages, I think FDE is fast becoming an essential security requirement for any organization that holds sensitive data. Data loss can be crippling both financially and legally, and protecting data with a well-implemented FDE policy will prevent many of these problems. File encryption such as Microsoft's Windows EFS (Encrypting File System) is a start, but EFS doesn't encrypt all of the data saved on the hard disk. Also, file encryption is nowhere near as efficient as drive encryption.

There are plenty of products that will make FDE a more practical solution. Windows Vista Enterprise and Ultimate editions, for example, include BitLocker full volume encryption (FVE). It encrypts the partition on which Vista is installed, and it does so on a sector basis rather than by files. This arrangement protects all data, including that in the paging file, hibernation file and all system files. Other partitions can only be protected using EFS, but at least the EFS encryption keys are located on the OS partition. On the hardware side, Seagate has a hard drive that includes a special encryption chip that will make its data impossible for anyone to read -- or even boot up its PC -- without some form of authentication. (I'm a fan of using hardware tokens to reduce password management overhead, but it's an additional cost to consider.)


Tags: Data encryption techniquesData Protection EssentialsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Data encryption techniques
How to secure data backup
Too many encryption methods make secure communications difficult
Massachusetts data protection law has mixed impact on financials
RBS WorldPay agrees to market VeriFone end-to-end encryption
Download presentations from Financial Information Security Decisions 2009
Data encryption: Pre-implementation best practices
Data encryption: Lessons learned from implementation
Data encryption: Q&A with Eric Leighninger
Community banks to increase security spending, survey finds
Lessons learned: The State Street Corp. breach

Data Protection Essentials
By addressing data privacy, companies avoid public scrutiny
Lessons learned: The LendingTree case
Lessons learned: The Countrywide Financial breach
The Societe Generale fraud story: Keith White on fraud
Institutionalizing risk management for ongoing management support
Risk assessments: Internal vs. external
Putting risk analysis into words
Lessons learned: The Texas Insurance Claims Services case
Lessons learned: The Montgomery Ward breach
Lessons learned: The Citibank ATM breach

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Financial Security News Topics: Compliance, Management Strategy, Security Technology
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts