ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Tackling the threat from portable storage devices

Ruggero Contu Gartner

Published: 05 Jul 2004 17:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The impact of the latter goes beyond the commercial value of the data for two reasons.

  • There are different privacy laws in different countries. This means there is more risk of legal action if personal information — belonging to corporate clients or employees — ends up in the hands of an unauthorised third party.
  • Companies' reputations may be damaged as a consequence of information leaks. This is particularly the case for those operating in areas where client privacy must be preserved, such as the financial market.

What are company requirements and strategies for deploying these devices in the workplace?

  • Companies should forbid the use of uncontrolled, privately owned devices with corporate PCs. The prohibition should extend to employees, and external contractors with direct access to corporate networks.
  • Portable storage devices can undoubtedly provide very good practical benefits to a company and its workforce. And, in many cases, it would be unpractical and counterproductive to ban their use outright.
  • A controlled approach would be a safer option. This would involve adopting certain security measures in terms of overall organisation (policy) and specific tools (technology).

What are the best practices in managing these devices?

  • These general security recommendations can apply to a whole range of portable storage devices.
  • Adopt a suitable security policy on using portable storage devices
  • Create a specific policy to help outline company guidelines on using portable storage devices by specifying if, and when, they can be used.
  • Managers should advise on the main procedures to be followed for the eventual use of such devices; for instance, to confirm the need for password and security protection (encryption) of stored corporate data. This will also help mitigate risks from loss or theft.
  • Make provision for training to increase awareness of the need for security in this area. A security-conscious workforce will be less likely to unwittingly leak sensitive information, by misplacing a storage device, for instance.
  • Use tools to help manage port access of USBs and FireWire.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
293 out of 553 people found this useful


Full Talkback thread

1 comment

  1. A threat still ignored sas410

Company/Topic Alerts

Create a new alert from the list below:



Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Should a security professional have a...

My own experience and talking to colleagues has prompted me to wonder whether the day has arrived that security professionals will need a legal background. The information security... More

1 comment

Transys comment speculation

I've been pondering why it's so difficult to get any official comment out of any of the organisations involved when it comes to what is happening with Transys. Transys is the consortium... More

Post a comment

Wallet Phones Are Coming:Visa Should J...

Wallet Phones Are Coming:Visa Should Jump On Board Author: Eric Everson, Founder MyMobiSafe.com I have touched on the subject of wallet phones (a mobile handset capable of eliminating... More

Post a comment