| | | RssFeeds
 
Get Free Newsletter Search   Search Search
         

Follow Us:

 
 
NC Print 
February 2010
Editorial
Four factors to consider before firing up that DLP solution
By Invitation

»The Analyst Angle

»ProductivIT

»Technology & Risks

How to plug the loopholes in two-factor authentication
Google Wave: An experimental ride
Managing Document Mammoths

» Jigar Shah

» Vidhii Partners

How The Koobface Worm Gang Makes Money
Zoeb Adenwala
On the Record

»Andrew M Dutton

»Jim Wagstaff  

Printer vendors don ‘consultant’ hat to push MPS
Case Study

»FT Rides Web 2.0 Wave Securely

»Eko’s Mobile Platform Accelerates Financial Inclusion

»Open Source Infrastructure Management tool helps JSL reduce downtime

5 points to make when your CEO cries cloud
How to be a guinea pig and not get slaughtered
Cisco launches enterprise social network solution
Top 10 security challenges for 2010
In the News
 EDGE 2009

Read More About the Best IT Implementations in the Country

 
       Read more >> 

Archive
 

Tech Tracker


 Lock Down Your Data Where it Lives

Encryption keeps a check on data theft—just don’t lose your keys

 By Peter Morrissey

 


Why bring encryption into the glass house? To paraphrase bank robber Willie Sutton, “because that’s where the data is.”

To date, most data center security efforts have been focused on protecting against Internet threats.

 

However, IT can no longer ignore physical security: Thieves recently broke into the Chicago data center of managed Web hosting provider C I Host and stole server hardware—for the fourth time. Meanwhile, backup tapes are frequent targets for theft because they’re often out of IT’s direct possession. The Privacy Rights Clearinghouse Web site documents more than 40 cases of tape theft since 2005, and it’s likely that far more were never reported. In the InformationWeek 2008 Strategic Security Survey, the theft of computers or storage systems was among the top five breaches seen as most likely to occur in 2009.


Clearly, encrypting hard drives and tapes is vital to protect data. So why aren’t organizations rushing to sign on? The complexity of managing keys is a top deterrent to ubiquitous encryption. After all, there are many ways to encrypt, but key management is where all these projects succeed or fail. And failure is most likely to occur several years out, after the hole has been dug quite deep. Some information must be kept for decades, after all, and storing the keys needed to access that data securely for 10 or 20 years is a challenge.

Fortunately, advances in managing keys as well as new options for encrypting data at each step within the backup process make it much less likely lost keys will come back to haunt you. Most of the vendors we spoke with understand the problem and are working to solve it. RSA’s Key Management Suite, for example, works with encryption products from RSA partners to give IT a single management point for all encryption keys. Encryption vendors also have started to build key management into their products or offer these capabilities as options for companies with modest requirements.


Tales of the Tapes
Security analysts love the idea of encrypting all data on the host before it’s even sent to a backup server. This guarantees end-to-end privacy and minimizes the number of places where mistakes can be made. And plenty of products provide this capability. Symantec’s NetBackup is a good example—just generate a key and click a box within the user interface to enable encryption of any data set. The backup server instructs the client to encrypt on the fly.


This approach has downsides, however. By encrypting data at the host, deduplication has to happen at the server. And encryption adds load to the server, lengthening the backup window and perhaps affecting performance. Moreover, encrypted data is supposed to be indistinguishable from random data, so it tends to render tape-drive compression completely ineffective. Since most tape drives claim a hardware compression rate of at least 2-to-1, server-side encryption can easily double your tape consumption.


But key management may well be the worst problem. Backup vendors are only now starting to add key management capabilities to their software; most still rely on the backup admin to handle management tasks. You’d think someone would take this off our hands.

 

l Page 2 l Page 3 l

Print this Page   E-mail this Page
RATE THIS ARTICLE
 Worse   Better 
Comment:*
First Name:*
Last Name:*
Company:
City:*
E-mail:*
Verification Code:*

Type the characters you see in the picture above.
 
  Reset

Comments >>

1
No Comments to display

Disclaimer >>

 

 

 Global CIO

Global CIO: The Top 10 CIO Issues For 2010

For CIOs, 2010 will require new emphases on customers, revenue, external information, and a passion for rapid change           
           Read More >> 

 

 Editor's Blog

What’s your storage strategy?

        

Read more >>  

 

 CIO Profile

Satish Pendse Muralikrishna K

VP and Head, Computers & Communication Division, Infosys Technologies

 Read more >>  

 

 International News

Facebook Hit By Clickjacking Attack

Social network targeted by emerging brand of attack that's hard to kill

 Read more >>

 

        

 Work Smart

Archive your mail      


Read more >>  

 

ADVERTISEMENTS >>

 
Powered By: ssCMS 2.2.0.0