Encryption from the database to the laptop PC

 

Connecting state and local government leaders

Vendor initiatives abound for securing sensitive data.

To encrypt or not to encrypt? When it comes to protecting sensitive data, there really is no choice. Sensitive information, whether transmitted over a network or stored in databases or on laptop computers, must be encrypted to protect against theft and misuse.

With the latest data theft involving a Department of Veterans Affairs employee whose stolen laptop contained the Social Security numbers and other personal information of 26.5 million veterans, experts say organizations should be looking for products that can protect data regardless of where it is.

RSA Security launched an initiative last week to offer companies and government agencies a more comprehensive approach to enterprise data protection. The aim is to protect sensitive data any place it resides: at the application-level, within databases, in files and operating systems, on laptop PCs and mobile devices, and in storage.

RSA's framework also focuses on managing encryption keys, access control and authentication functions.

At the heart of the company's initiative are the new RSA Key Manager Partner Program and a strategic partnership with Protegrity, a developer of data security management solutions. Managing encryption keys generated by disparate applications requires integration with data protection products. The partner program will allow vendors to combine their products with RSA Key Manager.

The program is a good move, said Paul Stamp, a senior analyst at Forrester Research. 'Right now we've got a mess,' he said. Products exist to encrypt laptop PCs, databases, file servers and data in transit, but 'none of them talk to each other,' he said. RSA's initiative will help establish a central broker so the right people can access the encryption keys they need to get their data, he said.

Protegrity and RSA plan to provide product integration between RSA Key Manager and Protegrity's Defiance DPS and VPDisk by the end of the year. Defiance DPS is enterprise software that helps secure sensitive data in databases. VPDisk secures sensitive files and encrypts structured and unstructured information.

Organizations are looking for ways to manage encryption enforcement policies across files and databases, said Paul Giardina, senior vice president of marketing at Protegrity. 'The RSA relationship is a nice fit' because keys can now be managed centrally across an organization with consistent policy enforcement, he said.

RSA is focusing on the infrastructure for managing user access rights, said Chris Parkerson, senior product marketing manager at RSA. Its Key Manager works with RSA Data Security Manager, RSA ClearTrust Web access management software and RSA SecurID authentication solutions. The program will allow RSA to work with other vendors to secure information from its inception to the time it is stored or destroyed, he said. The company is negotiating with vendors that provide encryption for laptops and back-end storage systems, Parkerson added.

Meanwhile, Ingrian Networks is taking a different approach by storing encryption keys on a security appliance rather than on servers where encrypted data resides, as in the case of most software-based encryption products.

The company's DataSecure Platform consists of five hardware appliances that encrypt data on servers and in databases. Two of the devices comply with Federal Information Processing Standards ' the i315 and i325 ' providing the level of security for encryption keys that government agencies require, said Derek Tumulak, director of product marketing at Ingrian.

The DataSecure Platform consists of three components: the hardware appliance; the Network-Attached Encryption Server, which runs on the appliance; and the NAE Connector, software that is installed on Web or application servers or in databases and acts as an interface with the appliance.

If an employee downloaded sensitive information such as Social Security numbers to a laptop PC and it was stolen, the thief would not have the correct encryption key to gain access to the data, Tumulak said.

Products that encrypt entire disk drives would further protect laptop users. WinMagic recently released a version of its encryption software for individual and home office or business users. MySecureDoc Personal Edition, which runs on Microsoft Windows 2000/XP, protects data on desktops and laptop PCs by encrypting the entire hard drive before the operating system displays the log-on screen.

The product is built on the same FIPS-based encryption engine that the company's enterprise edition uses, said James Armstrong, director of North America sales at WinMagic. Some of the networking capabilities have been removed, but MySecureDoc offers the same Advanced Encryption Standard 256-bit encryption that SecureDoc offers. That product provides full-disk encryption for agencies such as the Homeland Security Department, the National Security Agency and the Royal Canadian Mounted Police.

NEXT STORY: The Pipeline

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.