StrategiesEncryption Challenges for GovernmentBy Stacey McDaniel
It has been two years since a Veterans Administration laptop was stolen in a widely publicized case that prompted new endpoint encryption guidelines. In spite of the guidelines and public pressure to improve security, a February 2008 report by the Government Accountability Office (GAO) found that some agencies are still not properly encrypting remote and mobile devices. With sensitive and confidential information constantly passing through agencies to employees, remote workers, contractors and others, neglecting endpoint security opens up an agency’s data to unauthorized -- and unnecessary -- exposure. Vulnerable endpoints Applying encryption to each endpoint is the best way to protect data from exposure. Theft or loss of a computer or other data-storage medium made up 46 percent of all data breaches during the period of January 1 to June 30, 2007, according to new research. The bottom line: An unencrypted device falling into the wrong hands can spell big trouble for a government organization. Admittedly, managing encryption for each endpoint device inside an entire agency is a complex and daunting task. Here are some of the challenges an agency’s IT staff needs to factor in when considering an endpoint encryption solution:
Despite the challenges, some agencies have successfully encrypted endpoints. The Veterans Administration was one of the first agencies to apply full-disk encryption to tens of thousands of laptops and other mobile devices. The Federal Trade Commission encrypted hundreds of laptops and has also fulfilled requirements for two-factor authentication for remote access, as well as a time-out function for mobile devices. Conclusion
Stacey McDaniel has been writing about high-tech issues for more than six years. |
ADVERTISEMENT Related ContentFast Fact
"Some federal government agencies are still not properly encrypting remote and mobile devices." Podcast Audio ContentCIO Strategy Center is now available in audio format. This week's feature topic is: Patch Management and SecurityPlaytime: 9 min 28 sec |