December 19, 2007

Unlocking encryption management

As encryption technology becomes more user-friendly and manageable, more businesses are adding standalone encryption platforms to their IT security

Someday, encryption features built into a wide range of IT products -- from operating systems and messaging gateways to hard drives and storage systems -- may work in concert to offer central policy enforcement across different types of network assets and devices.

Until that day arrives, however, companies embracing the tools have become dependent on standalone encryption platforms to give them distributed control and policy enforcement across their IT systems.

Long known as much for their complexity and demand for hands-on care and feeding as they have been valued for their protective qualities, encryption platforms are finally finding their way into a number of large businesses.

This growth in adoption has been driven by the proliferation of data protection regulations and based on the availability of products that address the hardest elements of encryption technology -- policy enforcement and key management, industry watchers contend.

"The performing of the encryption itself is something that generally belongs close to whatever type of data you are trying to encrypt, whether that is e-mail, network traffic, or a database, but companies are buying into technologies today that allow them to do centralized policy enforcement and key management," said Paul Stamp, analyst with Forrester Research.

"It's great in theory to say that all of this activity needs to happen in the infrastructure components themselves," he said. "But that's not a reality yet in terms of allowing for centralized management, so customers are turning to these platforms in the meantime."

End-users agree that encryption has long been a security process they desired to implement but couldn't stomach based on issues of complexity.

The arrival of more usable encryption technology over the last few years has helped eliminate some of the traditional roadblocks, according to some corporate users.

"From my previous experience with e-mail encryption, I had two major concerns with using the tools: Key management and any dependence on the end-user to make the systems work right," said Michael Gabriel, corporate information security officer for Career Education Corporation (CEC) a higher-education provider that operates more than 75 colleges, schools, and universities.

"I haven't ever seen an encryption project where management wasn't a major sticking point, that has been the history of the technology, but it seems that the vendors are finally getting it right," Gabriel said. "Compared to mapping the business process, putting the technology in place was a breeze. The only real sticking point was getting the data flow."

CEC is using encryption tools made by PGP in cooperation with its data leakage prevention and e-mail filtering systems to protect sensitive information being passed among its employees.

Gabriel said that PGP's embedded key management capabilities may be the most valuable aspect of the system -- a feature that simply didn't exist in the past.

Other PGP users echoed those sentiments, saying that encryption tools have advanced significantly over the past several years in terms of eliminating the management headaches that have made it challenging to deploy the systems on a wider basis.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »
jacky.chan8888 16-Oct-09 9:48am
So, there's a new SDK available on the ISN Manageability site, and it frankly needs some explanation. Plus just some description on what Remote Encryption Management is, since it hasn’t been discussed previously. To sum up in a sentence, Remote Encryption Management supports the ability to unlock an encrypted hard drive through vPro. This refers to both software encrypted solution (where the OS and a pre-boot authentication 70-443 exam are involved), or FDE encrypted hard drives where the encryption is handled at the hard drive level. This helps to solve a previous conflict if someone wanted to use both encrypted hard drives and vPro to wake up and patch a system when a user wasn’t present. Previously the systems had to be left unlocked overnight, or a user had to be physically present 642-066 exam to unlock the hard drive. Now, the credentials to unlock the systems can be passed to the system to unlock it from remotely, and allow the patching process to continue. This also enables some other use cases remotely out of band, such as securely erasing the hard drive once the machine is no longer in use to ensure that sensitive data is removed. The SDK contains both an example console that shows how the functionality could be integrated into an existing encryption solution, 642-892 exam and an ISO file that can be remotely booted using the IDE-R functionality to unlock the systems. It also includes the source for both of these components, to make the integration task into an existing solution easier. If the existing encryption solution already has a pre-boot authentication environment, the key component of the ISO (the ATAoverLAN bridge) can be integrated into the pre-boot authentication environment. Integration into a pre-boot authentication environment is actually a better performing solution, since the ISO image does not need to be loaded over the network before the hard drive can be unlocked.

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.