<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130099&AdID=209259&TargetID=2556&Segments=91,115,350,2549,2690,2943,3108,3448,8877,9991,100 60,13943,13985,14402,14497,14750&Targets=39,315,302,2164,2556,2625,2878,6529,10068,10537,10640&Values=34,46,51,63,77,87,91,102,140,203,222,227,279, 382,442,657,940,1311,1716,1767,1785,1925,1970,2299,2310,2327,2352,2678,2767,2862,2878,2942,3890,3904,4080,6236,6293,6325,6352,6389,6391,6392,6393,6 422,6440,6541,6567,6580&RawValues=&Redirect=http://www.apc.com/promo/get.cfm?keycode=e896w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/ee_LEAD_a.gif" WIDTH=728 HEIGHT=90 BORDER=0></A>
home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek 

Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers

Regulatory Resource   Threat Intelligence      Resilient IT      Boardroom Strategies      
Threat Intelligence / Strategies

Encryption Challenges for Government

By Stacey McDaniel

It has been two years since a Veterans Administration laptop was stolen in a widely publicized case that prompted new endpoint encryption guidelines. In spite of the guidelines and public pressure to improve security, a February 2008 report by the Government Accountability Office (GAO) found that some agencies are still not properly encrypting remote and mobile devices. With sensitive and confidential information constantly passing through agencies to employees, remote workers, contractors and others, neglecting endpoint security opens up an agency’s data to unauthorized -- and unnecessary -- exposure.

Vulnerable endpoints
When people consider endpoints, they usually think about desktops and laptops, but those are not the only endpoints that can pose a data security threat. All internal, remote, and mobile desktops and laptops, as well as PDAs and embedded devices such as flash drives, are vulnerable. All it takes is one device lacking the proper encryption to create a system-wide weakness.

Applying encryption to each endpoint is the best way to protect data from exposure. Theft or loss of a computer or other data-storage medium made up 46 percent of all data breaches during the period of January 1 to June 30, 2007, according to new research. The bottom line: An unencrypted device falling into the wrong hands can spell big trouble for a government organization.

Admittedly, managing encryption for each endpoint device inside an entire agency is a complex and daunting task. Here are some of the challenges an agency’s IT staff needs to factor in when considering an endpoint encryption solution:

  • A solution must work in accordance with current security policies and regulations (such as FISMA) directed at the agency.

  • An agency’s IT environment is often heterogenous, with a wide variety of endpoints running an array of systems, from Windows to UNIX to Linux and more.

  • The amount of information generated by government agencies continues to increase, and it is stored on a growing number of endpoint devices that need to be managed.

  • With headquarters in one location and remote offices and contractors in other places, many agencies operate in a decentralized environment, making it hard to enforce security measures and policies.

Despite the challenges, some agencies have successfully encrypted endpoints. The Veterans Administration was one of the first agencies to apply full-disk encryption to tens of thousands of laptops and other mobile devices. The Federal Trade Commission encrypted hundreds of laptops and has also fulfilled requirements for two-factor authentication for remote access, as well as a time-out function for mobile devices.

Conclusion
For government agencies, the protection of data has become more challenging then ever, especially as valuable data travels freely across various environments and is stored on an ever-growing array of endpoint devices, including PCs, laptops and removable storage devices. Well-publicized cases of stolen government laptops have prompted new endpoint encryption guidelines. Government CIOs should look for a scalable, agency-wide security solution that prevents unauthorized access to endpoints by using strong access control and powerful encryption. With proper endpoint security, agencies can mitigate the increasing risk of potential data loss.

 

Stacey McDaniel has been writing about high-tech issues for more than six years.

IT Strategy Center is a daily editorial resource offering innovative insights and strategies for building an integrated, secure and resilient IT infrastructure.

Articles by Topic
Spam and Viruses
Preparedness
Strategies
Related Content
Fast Fact

"Some federal government agencies are still not properly encrypting remote and mobile devices."
--A February 2008 report by the Government Accountability Office (GAO)

Sponsor Tools
Podcast Audio Content

CIO Strategy Center is now available in audio format.

This week's feature topic is:


Risks of Wireless Email
Playtime: 8 min 23 sec



Download | Subscribe



Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR

RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.





Internet Evolution









<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=132180&AdID=212017&TargetID=347&Segments=92,118,335,351,3108,3448,8879,10297,13986,14405,14 496&Targets=40,347,2625,2878,6527,10071,10470&Values=34,46,51,63,77,87,90,102,140,205,222,227,279,382,442,657,940,1431,1716,1767,1785,1925,1945,197 0,2256,2299,2310,2313,2327,2352,2678,2862,2878,3712,3714,3890,3904,4079,6236,6293,6325,6352,6389,6393,6422,6440,6489,6541,6567&RawValues=&Redirect= http://www.informationagenda.techweb.com/?cid=webtile_ms_bi" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/gml/IBM/Leveraging_infoagenda/tile.gif" WIDTH=125 HEIGHT=125 BORDER=0></A>

What's Hot at NWC
Editor's Picks
Network Computing Reports
 


Advertisement
<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130106&AdID=209266&TargetID=294&Segments=94,117,334,353,2567,2692,3108,3448,4080,10296,1398 8,14467,14495&Targets=322,294,298,2625,2878,3348,10067,10535,10641&Values=34,46,51,63,77,87,90,102,140,206,222,227,279,382,442,657,940,1431,1716,17 67,1785,1925,1945,1970,2256,2299,2310,2313,2327,2352,2678,2862,2878,3712,3714,3890,3904,4079,6236,6293,6325,6352,6389,6393,6422,6440,6489,6541,6567 &RawValues=&Redirect=http://www.apc.com/promo/get.cfm?keycode=e897w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/ee_SKY_c.gif" WIDTH=160 HEIGHT=600 BORDER=0></A>


Microsite of the Week

< Advertisement >

Powerful Information at Your Fingertips

 










<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130079&AdID=209235&TargetID=42&Segments=93,116,352,2689,3108,3448,8547,9985,13942,13987,144 93&Targets=42,321,2625,2878,10069,10556&Values=34,46,51,63,77,87,91,102,140,204,222,227,279,442,657,1311,1716,1767,1785,1798,1925,1970,2299,2310,23 13,2327,2352,2678,2767,2862,2878,2942,3712,3714,3890,3904,4079,6236,6293,6325,6356,6359,6389,6391,6392,6393,6422,6440,6541,6567,6580,6643&RawValues =&Redirect=http://www.apc.com/promo/get.cfm?keycode=e901w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/isx_LEAD_a.gif" WIDTH=728 HEIGHT=90 BORDER=0></A>

InformationWeek Business Technology 

Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business 

ExpoSoftware ConferenceCSI - Computer Security Institute
Black 

HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight 

Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower 

Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights