topics that matter; ideas worth sharing

share a tip, submit a link, add something new

Encryption Convolution

August 10, 2006, 01:07 PM —  ITworld.com — 

Listen to the column "Encryption Convolution", or visit our Podcast Center to hear more by James Gaskin.

Get ready for the US Congress to help the IT business with some new regulations soon. After being embarrassed by the VA laptop fiasco, when unencrypted government data wandered the countryside, our federal leaders now consider themselves data security experts and will soon start passing laws.

We talked about laptop security back in May, so let's look at your backup security. Now's the time to amend your 2007 budget for better backup encryption, management, and storage protection, because corporate data backups are now targets of the federal meddlers.

The Disk to Disk to Tape products from Breece Hill (.com) make sense to me for middle to large companies as well as departments and remote offices. Combining a terabyte or more of online disk plus tape autoloaders in the same box provides two of the three critical backup requirements today: fast backup and restore from local hard disks, and tapes for offsite storage. What's missing? Encryption for the backup data.

Hardware vendors point to the backup software vendors for encryption support, and that makes sense. How about your backup software? Does it encrypt data on your local backup appliance hard disks? Does it encrypt data on tapes used for backup and archiving? If you're in a multi-location company and send tapes back and forth, how do you send the encryption keys between locations? And Breece Hill type systems, with both fixed and removable media, will require an extra encryption control layer to keep the local encryption keys separate from the keys used on tape cartridges.

Corporate desktop folder encryption took a hit recently when Microsoft pulled their new Private Folders encryption option. Users could designate individual folders as private and encryption kept them safe. Unfortunately, Microsoft didn't have enterprise support desks in mind, since they had no back door or remote unlock capability. Hello, Microsoft, have you ever known a large group of users who all remembered their passwords?

But this trend for data security will continue, including down to individual users. Corporate laptop users need disk encryption, but will that conflict with your user backup systems when those laptops are in the office?

It's going to become encryption convolution out there. Let's hope Congress doesn't "help" us too much and aggravate the problem even more.

ITworld.com

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff
Featured Sponsor

Get a broad understanding of important regulations and how you can make sure your site is in adherence.





Learn how VeriSign SGC-enabled SSL Certificates can help improve site security and customer confidence in the free white paper, "How to Offer the Strongest SSL Encryption." In this paper you will learn the differences between weak and strong encryption and what they mean for your site's performance.

Get VeriSign's free white paper: "The Latest Advancements in SSL Technology" and learn about the benefits of strong SSL encryption, Extended Validation (EV) SSL and security trust marks and what these SSL offerings can do for your site.

Now with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in this free VeriSign white paper.

More Resources