Understanding Data Destruction: What the CIO Needs to Know.

By Keith Hanks

Fri, May 18, 2007CIO News of stolen laptops that contain highly sensitive information surrounds us. Consider, for a moment, your organization and the data that resides on its laptops. Is there customer information, intellectual property, financial plans or other sensitive data? If your organization had a missing laptop would it become a news headline?

A single data loss can be devastating to a company. This can damage the company's reputation, in addition to costing the company millions of dollars. Such a breach can result in compliance violations on the federal and state level. On the federal level there are several disclosure laws already in place:

  • HIPAA (Health Insurance Portability and Accountability Act)
  • GLBA (Gramm-Leach-Bliley Act)
  • FISMA (Federal Information Security Management Act)
  • FACTA (Fair and Accurate Credit Transactions Act)
  • OMB Memo (M06-16)

According to analyst firm IDC, as much as 60 percent of corporate data resides unprotected on desktop and laptop computers. With that concentration of data, the organization must take precautionary steps to protect this sensitive information. Several solutions are available to protect the organization.


Encryption
Full disk encryption can help meet compliance requirements, but does not necessarily eliminate risk. Full disk encryption is transparent to the user, but can fail due to human error. It stops short of being a comprehensive solution if an unauthorized user gains access to the authentication credentials; should the user's password be compromised the data can instantly be decrypted and vulnerable.

Consider the internal risks. If a user becomes unauthorized (contractor term expires, employee resigns, employee is terminated) but has possession of the computer, encryption will again provide no protection. For encryption to be effective the thief must not have the ability to input the correct password.


Data Destruction
Data destruction is an emerging solution for the CIO to consider. The concept of data destruction is data on the computer is more important than the hardware, and the organization must ensure the data is destroyed with certainty and verification. Once an organization has determined the computer is unable to be recovered physically, the company can ensure the data can not be accessed. By combining encryption with data destruction Beachhead Solutions' Lost Data Destruction (LDD) offers a final step.

LDD works through client/host communication. Should a computer go missing, the administrator marks the computer as unrecoverable. The next time the computer obtains a network connection and checks in the computer will be notified of the status change and will begin the self destruction sequence. This process is straightforward, but is dependent on the computer obtaining a network connection. There are additional triggers that can be put into place should the laptop not connect to the Internet. Such triggers are based on administrator-created preset rules including, number of unsuccessful login attempts and maximum time allowed between client/host communication events. The customizable rules allow for data destruction of a particular file, folder or the entire PC.

Mobile Security

Loading...
Security MarketSpace
8 Tactics to Combat Vulnerabilities
This white paper reviews 8 key elements of vulnerability management and provides advice on combating known vs. unknown vulnerabilities. Learn more »
Email and Web Threats Require a Layered Defense
Learn how web threats are changing and how using a layered defense strategy can give you the security you need. Learn more »
Take Fraudsters Out of the Game
Easily identify account-device relationships and get data for in-depth forensic analysis. Learn more »
Mobile Security Landscape
This paper examines the current mobile security landscape, including myths surrounding the risks and threats, and how organizations can establish a solid mobile security strategy. Learn more »
Reducing Energy Costs in Your Data Center
This white paper examines the most common roadblocks to improving data center efficiency. Learn more »
Security convergence equals network security cost savings
Security convergence equals network security cost savings Learn more »
IBM ISS X-Force Threat and Risk Report
Read this Trend and Risk report from IBM® ISS X-Force® to learn statistical information about all aspects of threats that affect Internet security, including software vulnerabilities and public exploitation, malware, spam, phishing, web-based threats, and general cyber criminal activity. Learn more »
 
SPONSORED LINKS
 

Mobile Security: The Essential Ingredient for Today's Enterprise

IDC White Paper: CCM for IT Compliance and Risk Management

Keeping Your Members Safe from Online Scams and Predators

Learn about the growing threat of insider data theft.

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths

White Paper: Improve Agility with Operational Responsiveness

White Paper: Legacy Tools: Not Built for the Helpdesk

Taking a Seat at the Executive Table: The Reality of Virtualization

White Paper: Next Generation Remote Infrastructure Management

Seven Design Requirements for Web 2.0 Threat Protection

Generation Remote Infrastructure Management - Changing the Paradigm

Cloud-Based Email Management: Opinion Shifts In Favor

eBook: How Can You Make Your People Productive Anywhere?

Achieving Business Agility with Application Grid

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion

Read the RSA report: Security for Business Innovation

Webcast: Looking to the Cloud for Email and Collaboration Services

64-page prescriptive guide to security, compliance, and IT operations.

Keep your IT expertise up to date. Join the Intel Premier IT Professionals.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

White Paper: Managed Security for a Not-So-Secure World

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

White Paper: A Security Blueprint Delivered From within the Network

See how AT&T can help protect your network.

Webcast: Unleashing the Power of Customer Data

White Paper: 5 Best Practices for Smartphone Support

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

The Total Economic Impact of Network Security Intrusion Prevention

Join us at the US-Brazil IT-BPO Summit, on November 10th in New York.

Increase UPS efficiency without sacrificing protection.

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Lower IT Costs with Oracle Database 11g Release 2

White Paper: Visibility and the New Normal of Mobile Work

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Top Five CIO Challenges

Streamline IT Costs. Boost Performance with WAN Optimization.

Want to know how you can maximize employee productivity?

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

A new fleet of PCs with a total ROI in 10 months. Find your ROI.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

 
 
RESOURCE CENTER