SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Identity Management

How to protect your mobile data

How to protect your mobile data

By:  Galen Gruman  On: 19 Nov 2006 For: CSO (US) 

The simplest way to protect data on mobile devices is to not store it there in the first place. Encrypting data on mobile devices, or adopting remote access tools to stop information leaving the confines of the data center, are some other ways of protecting data.

It was two close calls that changed how Rob Israel thought about encrypting the data on his users' laptops.

A few years ago, a laptop at the John C. Lincoln Health System, a Phoenix-area hospital group where Israel is CIO, was stolen from an employee's office. It could have contained financial or (worse) patient information but, fortunately for Israel, "The laptop was brand-new and had no data on it yet," he says. Still, this pilfery and an earlier PC theft from a common work area (which resulted in a loss of noncritical data) pushed him to revisit his company's security strategy.

The result: Lincoln Health avoids storing data locally on users' computers -- PCs and laptops.

In today's workplace, it's impossible to eliminate mobile computing devices -- laptops, thumb drives, mobile phones, PDAs and iPods. If you follow the news, you know that dozens of organizations have had mobile devices lost or stolen, and many of them were not as lucky as Lincoln Health. Since California enacted a data breach notification law in 2002 (followed by 32 other states), there have been a host of embarrassing disclosures about missing computers, most recently at the U.S. Department of Veterans Affairs, the Federal Trade Commission, the Transportation Department, accounting firms Deloitte & Touche and Ernst & Young (three separate occasions this year), Wells Fargo and ING banks, Fidelity Investments, the YMCA and Chevron.

About half of the states' breach-reporting laws give companies a way to avoid disclosing such breaches: the use of encryption on the mobile devices. The other states' breach laws encourage the use of encryption, as do other privacy protection laws such as the federal Gramm-Leach-Bliley Act covering financial information, and the Health Insurance Portability and Accountability Act (HIPAA) covering medical information. Avoiding both the breach penalties and the other costs of losing critical data makes an encryption strategy well worth the effort, says Tim Mc­Knight, vice president and CISO at aerospace contractor Northrop Grumman. "We paid for our program with the savings from the first three laptops that were lost," he notes.

But encrypting data on mobile systems isn't a simple task. CIOs and CISOs have found that while the technology to encrypt laptop hard drives is pretty straightforward and simple to deploy, there are several aspects of mobile security for which technology is not yet solid, particularly for protecting data on removable media and handheld devices. That's why security leaders who have adopted encryption make sure to use other techniques -- both technological and managerial -- to protect their mobile data.

Encryption for laptops: full-disk or file-based?

The first decision when implementing an encryption strategy is whether to use full-disk encryption or file-based encryption. Because Windows XP comes with file-based encryption built in (as do Linux and Mac OS X), it's tempting to use that "free" technology. Anything stored in specific PC folders, like My Documents, is encrypted automatically. But this approach has a significant security flaw: It relies on users putting files in the encrypted folders.


Sign up for our Newsletters












Print |  Views: 1493   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Galen Gruman Galen Gruman is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Computer makers agree on full-disk encryption specs
Computer makers agree on full-disk encryption specsProtection for data at rest gets a boost as the world's top computer makers release final specifications for full-disk encryption across all drives. Read how this development could mean total computer lock-down
Is your mobility policy worth the paper it’s printed on?
Is your mobility policy worth the paper it’s printed on?Just because you draft an acceptable use policy for mobile devices, it doesn’t mean that your employees will understand it. An Info-Tech analyst explains why a little training goes a long way
Seagate ships self-encrypting laptop drives
Seagate ships self-encrypting laptop drivesThe company says unlike software-based encryption methods, its self-encrypting hard drives can be easily utilized with no learning curve. IDC Canada analyst David Senf weighs in
McAfee coming to an Intel laptop, MID near you
security vendor mcafee announced yesterday its plans to extend its products to intel-based laptops and mobile internet devices (mids).integrated data encryption and integrated mobile content security will be provided for laptops and mids using intel atom processor z5xx series and moblin-based software.intel's anti-theft technology and active management techn

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.