Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

How to Lock Up Laptop Security

Haven’t encrypted your laptop fleet yet? There’s no excuse for that choice anymore. Check out today’s smart strategies for improving laptop security — before the next machine disappears

Even before her state of California put a stake in the ground regarding public disclosure of data breaches, Christy Quinlan could see the wisdom in encrypting client data on mobile devices. Shortly after Quinlan became CIO of California's Department of Health Care Services in 2005, one of the agency's partners lost a computer. The contractor had to notify everyone who might have been affected, at a cost of several hundred thousand dollars: And while Quinlan's staff had not lost the laptop, they still spent much of the week before a holiday coordinating with the contractor to determine the possible scope of the security breach and then ensuring swift and proper notification. "Once information is on the loose, you can never get it back," Quinlan says.

California eventually created a state law that required the public disclosure of data breaches (quickly followed by most other states). But ironically, at the time of Quinlan's contractor incident, the state was still trying to figure out the right internal policies to protect data across its many agencies.

Issues include deciding what should be encrypted, how to recover the passwords that unlock encrypted data when users lose them or leave the company, and how to make passwords available to backup and client management software
After her experience, Quinlan decided she could not wait for that final internal policy, so she directed her staff to encrypt all data on the field force's 2000 laptops within 30 days, which they did using GuardianEdge's software. California's law exempts encrypted data from requiring public disclosure, since the data would be inaccessible to thieves. Quinlan gambled that the statewide policy direction under discussion would ultimately be approved, and that even if she had to throw out her agency's specific system, the cost was justified because she was reducing so much risk by adding encryption.

As it turns out, the encryption effort proved less difficult than she'd feared, thanks to systems and infrastructure already in place. The agency had recently updated its laptops to support Windows XP, providing sufficient computing and storage capabilities as well as an operating system to support enterprise-class encryption software. And the agency had a client management system in place to update users' laptops with new software and enforce encryption and other security policies automatically.

CIOs should take Quinlan's experience to heart, says Paul Kocher, president and chief scientist of consulting firm Cryptography Research. "Anyone not doing it has no excuses anymore," Kocher says: Encryption technology is now widely available and proven.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: ACT, BlackBerry, Department of Health, Microsoft, Motion, PGP, VIA

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • Ten ways to save money with IBM Tivoli Storage Manager
    According to a recent report by Gartner, “By 2014, at least 30% of organizations will have changed backup vendors due to frustration over cost, complexity and/or capability. ”However, replacing a backup infrastructure can be a painful and disruptive process. The best replacement solution will beone that not only addresses these issues, but also demonstrates significant cost savings, enables a rapid return on investment and ensures a seamless transition.This white paper describes 10 ways that IBM® Tivoli® Storage Manager solutions can help organizations save money while addressing their data storage challenges, including those associated with exponential data growth.
    Learn more »
  • New Mobility Requires a New Network Strategy
    Computing has gone through several major transitions through the ages, each of which raised the value of the network and dramatically lowered the cost of computing. In the years after its birth in the mainframe era, the computing industry shifted to client/server and then Internet computing. Today, we are beginning yet another major computing revolution: the shift to mobile computing. This revolution already allows us to carry mini computers, called “smartphones,” in our pockets. This shift will drive down the cost of computing even further and drive up the value of the network, forever changing its role in organisations. Read on.
    Learn more »
  • 2-Layer BPM: Oracle's Unique Strategy Towards Exceptional Agility and Business Process Efficiencies
    Today, a new approach to BPM — the use of BPM and SOA together in a layering strategy — offers built-in smartness and high configurability. This dynamic approach to business process management is based on context and content. It offers agility throughout an organization, and it can dramatically increase productivity and time-to-market.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments

HP and IDG news, product videos and resources