SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Technology

Opinion: Data Security Tips for CIOs

Opinion: Data Security Tips for CIOs

By:  Joanna Jasper  On: 14 Apr 2008 For: ComputerWorld Canada Creator

Security issues are on the minds of all CIOs these days. Whether the CIO of a 1,300-student liberal-arts college or that of a 13,000-employee Fortune 100 company, never before has the issue of data security been more important.

Security issues are on the minds of all CIOs these days. Whether the CIO of a 1,300-student liberal-arts college or that of a 13,000-employee Fortune 100 company, never before has the issue of data security been more important.

Besides a record-breaking year of data breaches, legislation such as Sarbanes-Oxley, Gramm-Leach-Bliley and HIPAA mandates new security protocols that must be followed or violators face severe penalties.

At Catawba College, network, computer and information security concerns have been a major focus of our information technology work for the past several years, as evidenced by our campus-wide 802.1x network authentication and our CatNet Connect process to clean and secure student computers before allowing them to connect to the residence hall network.

As we faced the prospect of a hardware refresh for about 500 personal computers on campus, it was only natural for us to be concerned about how to dispose of the outgoing equipment in a secure and environmentally friendly way.

For the environment's sake-and to benefit the community-we decided to donate our used equipment to a local organization that trains middle school and high school students to refurbish computers, which are then donated to needy families. From an information security perspective, it was essential that we ensure all confidential data was completely eliminated from the hard drives in a manner that would preserve the drives.
As we investigated ways to completely remove the data from hard drives in a nondestructive manner, we immediately eliminated two options-degaussing and mechanical destruction-because both failed to meet our reusability criteria. The magnetism of degaussers destroys the read/write head, rendering the hard drive inoperable. And mechanical destruction is very harmful to the environment because it requires drives to be ground into tiny pieces, releasing a variety of toxic chemicals.

Although they passed the reusability test, the software overwrite methods we had traditionally been using to clear hard drives fell short in some key areas. First, these methods are labour-intensive and very time-consuming. A typical 120GB hard-drive triple-overwrite process can take four hours or longer to complete and the process must be physically monitored for security purposes.

Second, these methods lacked the level of automated logging that we required. For information security and auditing purposes, it was imperative that the hard-drive sanitization procedure be completely documented, without exception, and without the possibility for error.

Ultimately, we chose the Digital Shredder, from Ensconce Data Technology. The Digital Shredder is about the size of an average suitcase, has a familiar touch-screen interface and accommodates up to three hard drives. It sanitizes drives by activating the Secure Erase technology built into the hard drives by the manufacturer.

Secure Erase is a very fast method of nondestructive drive sanitization. It is defined by NIST SP 800-88 as "purge" technology and is recommended as the best nondestructive method available for sanitizing hard-drive data. Security measures include three independently locking hard-drive bays, as well as detailed audit logs.


Sign up for our Newsletters












Print |  Views: 568   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Joanna Jasper Joanna Jasper is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Seagate ships self-encrypting laptop drives
Seagate ships self-encrypting laptop drivesThe company says unlike software-based encryption methods, its self-encrypting hard drives can be easily utilized with no learning curve. IDC Canada analyst David Senf weighs in
How dangerous user behaviour puts networks at risk
How dangerous user behaviour puts networks at riskRecent research from the Ponemon Institute revealed that a majority of users disobey company security standards -- and they do so knowingly. In addition, survey data just released by RSA shows that trusted insiders create data exposures of extraordinary scope through their everyday behaviours. Here are some behaviours to watch for and guard against.
Are you in line for a security spending cut?
Are you in line for a security spending cut?Organizations that have reached a high level of IT security practice maturity can safely reduce spending to between 3 and 4 percent of the IT budget by 2008, according to research firm Gartner.
Federal Government Secure Channel boondoggle finally being made visible
an article by kathryn may of the ottawa citizen exposes the "secure channel" boondoggle. this is the same project that was mentioned in the
Wireless LAN security vs. convenience - walking the tightrope
by joaquim p. menezes - “security vs. ease of use” – is a conundrum a lot of network managers face when it comes to wir
CIBC's could-be security breach raises BPM issues
what makes you feel better: knowing that your personal information has been lost by a major financial institution,
blog comments powered by Disqus