Home > Storage Technology Tips > Data storage management > How to secure laptops in seven steps
Storage Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

DATA STORAGE MANAGEMENT

How to secure laptops in seven steps


Kevin Beaver
06.06.2007
Rating: -3.40- (out of 5)


Storage technology learning materials
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


What you will learn: This tip outlines seven essential steps for protecting your company's laptops and offers practical advice on what you can do to get beyond the basics and develop a new mindset about laptop security.

Do you know where your laptops are and how they're being handled? Probably not -- that's the essence of mobile computing, right? Perhaps the more important issue is whether or not you feel confident that sensitive information stored on your laptops is secure from malicious abuse when the time comes for loss or theft. I'm convinced most people aren't ready, and that the vulnerability is much greater than we think it is.

Mobility has become a business necessity. The benefits are obvious -- the risks, not so much. ''For an eye opener, just skim through A Chronology of Data Breaches Since the Choice Point Incident at privacyrights.org. All the laptop-related incidents will make your head spin!

Laptop security essentials

The following are seven essential requirements for locking down laptops:

These basic controls are essential. You may even need more depending on your circumstances. One thing's for sure -- never, ever rely on your users to do the right thing to protect their laptops all the time. Whether through carelessness, ignorance, or malice, users can and will create laptop security exposures.

Encryption's not everything

For those who do encrypt their laptop drives, there is a certain false sense of security. Encrypted doesn't mean secured. It's all the business processes and usage requirements associated with encryption that typically cause problems. There are a lot of ways to exploit basic encryption controls, but there's one vulnerability in particular with laptop encryption that stands out to me. Here's the scenario: A user is logged into his laptop (often with full admin rights/access). His screen is not locked or his screensaver has a too long timeout period. He leaves his desk or



seat, table, room, as is the case in restaurants, coffee shops, airports and hotels. A criminal comes by and takes the laptop with the screen unlocked and the user still logged in. The criminal now has unfettered access to the entire system for as long as the battery holds out or until he can get the laptop plugged into a universal power supply. Obviously, not good for business.

I see the potential for this scenario literally every time I'm in a public place where laptop users happen to be. Who's to say this can't happen very easily, especially in a crowded area. It's textbook -- the laptop user, trusting by nature as humans are, thinks to himself, "I'm just going to step away real quick -- everything will be safe. If someone tries to do anything, others will see it happening and stop him." Despite what we think will be done, there's something called "bystander apathy" whereby "good Samaritans" don't really do what we think they're going to do to help.

The problem is not going anywhere

The bottom line is that bad things are happening, and we can't rely on others to keep our laptops safe. Inject a good dose of technical controls backed up with policies that are actually enforced by management. This combined with a trust no one stance is the best form of vigilance for protecting your laptops. If you do experience the unfortunate do laptop breach, I've outlined what to in this article from SearchMobileComputing.com.

Sensitive information that used to be protected in a highly controlled storage environment now has feet. With laptops being the majority of new computers being shipped, combined with the fact that very few of them end up with an encrypted disk or partition, we've got a problem on our hands that's here to stay.

A new mindset is required for mobile storage security. Rise above all the laptop encryption noise and at least implement the basics. Like all things security related, a little common sense goes a long way.

About the author: Kevin Beaver is an independent information security consultant, speaker and expert witness with Atlanta-based Principle Logic LLC. He has nearly two decades of experience in IT and specializes in performing information security assessments revolving around compliance and risk management. Kevin can be reached at kbeaver at principlelogic.com.

Rate this Tip
To rate tips, you must be a member of SearchStorage.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Data storage management,   Secure data storage,   Data Protection,   Storage Encryption FAQ,   Related information,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Data storage management
Choosing a storage system for data archiving
Green storage best practices control costs, increase energy efficiency
Best practices for using server virtualization in your storage environment
Best practices for effective thin provisioning
Three tips for ensuring a user-friendly email archiving system
Top tips when evaluating a storage automation product
Guidelines for implementing virtualization in your storage infrastructure
The value of easy-to-use SAN storage
Pros and cons of storage capacity management tools
What are the differences between SATA II vs. SATA I?

Secure data storage
Isilon targets enterprise NAS with Backup Accelerator, N+2:1 parity
Storage Decisions Chicago 2009 Session Downloads
Storage Decisions Session Downloads: Disaster Recovery Track (Chicago 2009)
Storage Decisions Session Downloads: Data Retention & Retrieval Track (Chicago 2009)
Data on the brink
Sun jumbles key management picture
HP, IBM, EMC propose encryption key management standard
Hifn offers NIC with compression and encryption
Jingle bell storage: What to buy a geek for the holidays
Storage Decisions San Francisco 2008 Session Downloads

Related information
Ten reasons storage security is critical
How to reduce risk with storage security policies
Laptop encryption the hard(ware) way

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
hard drive shredder  (SearchStorage.com)
Storage as a Service (SaaS)  (SearchStorage.com)
storage encryption  (SearchStorage.com)
storage security  (SearchStorage.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Find Data Backup Analysis and Server Storage Channel Solutions

The Data Domain Data DeDuplication Center - Data Retention, Replication and Recovery

TechTarget Storage Media
Storage Magazine View this month\\'s issue and subscribe today.
Storage Decisions Apply online for free conference admission.
SearchStorage.com
HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts