Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Another Tool for your Awareness Arsenal | Main | Another U.S. Veterans Affairs Computer Stolen: This One With Personal Information About 1,600 Vets »

Encryption...Just Do It!

I am a big advocate of encryption. It is such a great tool for protecting sensitive and personally identifiable information (PII), particularly for such data that moves...while on mobile devices, storage devices, and while being transmitted through networks. Historically it was a challenge to implement.

In the past few years implementation has been getting much easier, and continues to improve. However, it is still no surprise, but yet a disappointment, that a recent study from Credant Technologies, Inc., yes, an encryption solution vendor, found that out of 426 IT practitioners interviewed throughout the world, 88% know sensitive data and PII is on their personnel's mobile computers, but the only 20% have deployed encryption for such devices. Note the encryption is deployed; I would bet that the actual amount of PII and sensitive data encrypted on those devices is actually much lower.

"The Credant survey asked respondents to list reasons why their companies hadn't adopted encryption. Fifty-six percent said it was due to a lack of funding; 51% said encryption was not an executive priority; and 50% said they were impeded by limited IT resources."

I believe there are other factors the study probably did not consider as well. Most of the companies I speak with have not even defined or classified their sensitive data and PII. They also really have no idea where all this data is located. Some were very surprised to find that significant amounts of sensitive data and PII were located on mobile computers and storiage media, even though they had policies against put the data in those areas.

Another issue is personnel using their own personally-owned computers at home and other places away from the work site to process, access, store and otherwise use business sensitive data and PII.

It will be great when some day operating systems come with full disk encryption standard, and transparent to the user, won't it?

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/230

Listed below are links to weblogs that reference Encryption...Just Do It!:

» The Daily Incite - November 3, 2006 from Security Incite: Analysis on Information Security
November 3, 2006 - #149 Good Morning: Today I'm inspired. People overcome great hardships every day and a lot of other people decide they are going to thrown in the towel and accept the path they are on. Ultimately, those kinds of decisions are [Read More]

Comments

hi nice site.

hi all. nice site. by.

hi. nice blog . thanks.

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.