Endpoint security gets complicated

By Tim Greene, Network World |  Security, endpoint security Add a new comment

Users say protecting network endpoints is becoming more difficult as the type of endpoint devices -- desktops, laptops, smartphones -- grows, making security a complex moving target.

The problem is compounded by the range of what groups within corporations do on these devices, which translates into different levels of protection for classes of users on myriad devices.

Deciding the appropriate device defense becomes the No. 1 job of endpoint security specialists, says Jennifer Jabbush, CISO of Carolina Advanced Digital consultancy. Depending on the device and the user's role, endpoints need to be locked down to a greater or lesser degree.

ZeuS botnet code keeps getting better… for criminals

For instance, Wyoming Medical Center in Casper, Wyo., has four classifications of PCs -- open PCs in hallways for staff use; PCs at nursing stations; PCs in offices; and PCs on wheels that move between patient rooms and handle very specific, limited applications, says Rob Pettigrew, manager of technical systems and help desk for the center.

Pettigrew is deploying Novell ZenWorks to 850 of the center's 900 PCs in order to make sure each class has the right software. With 110 applications and 40 major medical software systems to contend with, that makes a huge matrix of machine types and restrictions to contend with, he says.

In addition, physicians in affiliated clinics can access via SSL VPN, but they are limited to reaching Web servers in a physician's portal that is protected from the hospital data network. Some Citrix thin-clients are also used to protect data from leaving the network, but overall the strategy for unmanaged machines is a work in progress, Pettigrew says. "We're hoping to get more help desk," to deal with the external physicians, he says.

One concern that can be addressed by endpoint security is data privacy, which is paramount for the Los Angeles County Department of Health Services in California, says Don Zimmer, information security officer for the department. He supports about 18,000 desktops and laptops and operates under the restrictions of Health Insurance Portability and Accountability Act  regulations. That means disk encryption, he says.

"If it's not encrypted and there is a breach, then we have to start calling people," he says. To avoid violating patients' privacy and a loss of public trust the department encrypts the drives of all the PC endpoints with software from PointSec.

Equally important is keeping sensitive information off movable media that can plug into USB ports. The department uses Safend's USB Port Protector product that either denies access to sensitive documents or requires that they be encrypted and password-protected before being placed on the removable device.

Zimmer says he is looking into data-loss prevention software as well that can restrict the access individual devices have to data. While the technology can be effective, it also requires that businesses locate and classify their data so they can set policies surrounding it -- a job that can seem insurmountable depending on how data has been stored.

For Pettigrew, this means finding the 5% of sensitive data stored outside the medical center's electronic medical records system.

Rather than deal with many vendors for specific endpoint protection products, some businesses opt for endpoint security suites, such as those that evolved from the antivirus roots of vendors including McAfee and Symantec.

Sam Ghelfi, CSO at financial firm Raymond James, opted for Sophos' Endpoint Protection and Data Security Suite, which offers firewall, antivirus, data-loss prevention, antispyware, encryption and network access control (NAC). The company wants tight control over what Web content is available to users to minimize the malware coming in via basic Web browsing. The company uses a Sophos Web proxy that filters sites based on reputation but also the content that sites return.

Mobile devices that could contain confidential company information are disk encrypted, again using Sophos agents. If a device is lost or stolen, the encryption key is wiped out making it impossible to decrypt the contents of the hard drive.

Ghelfi says he believes in personal firewalls on individual machines because they can stop groups of devices from talking to other groups. Centrally managed, they can reveal network traffic patterns, he says.


Originally published on Network World |  Click here to read the original story.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question