SAFELY USING PORTABLE DEVICES

Securing Data When Using Portable Devices

  • Can you restrict the devices that connect to your PCs?
  • Do you know if unauthorized files are being copied off of your PCs? Can you prevent it?
  • How can workers safely and securely share data via portable storage devices?
  • Can you protect authorized data transferred to portable media when employees take work home?
  • How can employees securely distribute sensitive documents attached to emails?

Portable devices (hard drives, USB keys, etc.) and removable media (CDs and DVDs) are ubiquitous in the workplace, driving productivity and new business models, but represent a real risk to legally protected, sensitive and confidential data. According to the Open Security Foundation Data Loss Database, during a 10 month period in 2008, 24 million records and 34% of all records reported lost were as a result of these devices and media. With an average cost to organizations of $200 per record lost, the costs of these data breaches are staggering.

As a result, enterprises need solutions that protect data while providing the flexibility needed to enable business.

contact

Addressing real-world problems

There’s a simple way to learn if your critical data is at risk from portable devices. Are the following scenarios being addressed?

  • Can you restrict the devices that connect to your PCs?
  • When workers in your environment need to transfer or share data via portable storage devices, how do you ensure it is always secure?
  • If employees need to take work home, or to share information with customers, partners, or suppliers on portable media how is the information protected?
  • Do you know if data is being copied off of your PCs in an unauthorized manner? Can you prevent it?
  • When you need to email sensitive documents how do you protect your information?

GuardianEdge solutions secure data for these five portable storage “use cases”, allowing organizations to productively use portable devices and storage media while protecting themselves from the risks of data theft or loss, as well as regulatory non-compliance.

How can you restrict use to approved devices?

Many organizations have written policies that exclude the use of certain devices with their systems, but lack the ability to monitor ongoing usage and appropriately set and enforce policy restrictions. Solutions require:

  • Monitoring and reporting to identify legitimate business uses that need to be supported while also exposing risks and unauthorized usage
  • Policies that are easily tailored to specific organizational needs – Highly flexible configuration options that allow white listing for appropriate devices and prevent connection to non-approved devices.
  • The ability to restrict how devices are used (e.g. read / write / block, etc.)
  • Tight integration with directory services so permissions can be tailored by role, organization or other criteria

How can workers safely use portable storage devices and media within workgroups?

Secure movement of information within workgroups is a special problem. To secure data, while encouraging productivity, a complete approach is needed that enable employees to continue to work productively while protecting critical data:

  • Monitoring the transfer of information to understand the business needs and determine the scope of appropriate usage policies
  • Implementing controls that permit the classes, types, and/or specific devices that are allowed
  • Applying data transfer policies that permit or deny the copying of specific file types to removable media
  • Deploying an encryption solution that secures the data stored on removable devices with workgroup key management while ensuring simple, seamless data transfer between systems

How can employees safely take work home?

The most common enterprise use for portable storage devices is enhancing flexibility and productivity by enabling employees to take work home. To do this requires a complete solution set that ensures security for critical data, access on remote systems and that is non-disruptive to user’s accustomed access to their computers and applications. Key elements to accomplish this include:

  • Policy-based regulation of the devices allowed to connect to systems, the data types that are permitted to be written to removable media, and the encryption of data stored on these devices
  • Mature key management infrastructure that enables easy access to encrypted data on machines not running the data protection software.
  • Strong authentication to ensure that only authorized users can access protected data
  • The capability to re-encrypt the data if changes are made to ensure end-to-end data security.

How can you prevent data theft resulting from the use of portable storage devices?

Insider threats account for a significant portion of data breach incidents. To protect against this threat organizations need the capability to:

  • Detect and prevent unauthorized use of devices
  • Restrict users ability to transfer data to only those cases where a business need exists
  • Monitor all data transfer activity to ensure that any potential violations do not go undetected

How can you securely distribute sensitive files by email?

When organizations need to distribute information to third parties, email is the most common communication method. The solution to securely distributing files by email is simple and straightforward—Send a self-extracting encrypted file archive. Such an archive can then be easily decrypted by the partner with the right password or smartcard at their end. To do this right, archives should be able to support a full file structure (files and folders), passwords and certificate-based multi factor authentication and the capability to be automatically renamed so that they can easily pass through firewalls.

GuardianEdge – The Leader in Enterprise Endpoint Data Protection

To provide solutions to these five critical use cases for keeping data secure on portable devices, the organization’s perimeter of protection must be pushed down to each endpoint. Doing this requires the appropriate safeguards combined with simple, cost-effective centralized management. GuardianEdge Device Control and GuardianEdge Removable Storage Encryption combine to provide this solution—allowing organizations to regain control over the data moving to devices and protecting that data for authorized use.

GuardianEdge Device Control provides the detailed, monitoring, auditing, and alerting for device connections, file transfers and wireless network connections needed to understand usage and highlight risks. It then allows organizations to restrict usage of ports, device connections and file movements to enable only the authorized transfer of information to those devices.

GuardianEdge Removable Storage Encryption then protects data from physical loss or theft of the device after transfer with encryption, providing group based operation modes that are transparent to end users, an access utility that makes it simple to take work home while protecting data and the capability to create self-extracting file archives.

As part of the GuardianEdge Data Protection Platform, these products simply and cost-effectively deliver the safeguards, centralized management, low implementation, training and support costs that enterprises require to successfully deploy endpoint data protection.

A trusted, proven partner, GuardianEdge solutions have the highest deployment success rates and millions of licenses deployed.

Email Page Print Page Bookmark and Share top of page