In Depth

How to Keep Portable Data From Escaping

Laptop and handheld computers are easy to carry around...and just as easy to steal or lose. Here's a buyer's guide to options for protecting the data they hold.

By Sarah D. Scalet

May 01, 2006CSO — As far as Joseph Gimigliano is concerned, the best way to deal with a laptop or handheld device being stolen isn't to run down the street yelling, "Stop, thief!"

"We're trying to make what they steal not valuable," says Gimigliano, associate director of architecture and security at Purdue Pharma, the Stamford, Conn.-based company that makes painkillers such as OxyContin. "It's not the laptop that's of value. It's the data that's on it."

To that end, Purdue Pharma, like a lot of other companies right now, is testing methods of encrypting data on laptops, starting with the least expensive option of all—using features built into Microsoft products that Purdue already uses. Compliance is a big driver, especially for companies that have personal information about customers saved on portable devices. That's because some of the emerging privacy breach disclosure laws—California's SB 1386, as well as a data accountability bill being considered in Congress—don't require companies to disclose a breach if the personal information on a device was encrypted. The idea behind such rules is that even though the device went missing, the information on it wasn't really compromised.

"Any reasonable type of encryption method will get the 'hackee' off the hook on disclosure," says Erika S. Koster, a partner in the intellectual property group at Oppenheimer Wolff & Donnelly, a law firm in Minneapolis. Koster notes that whether a company opts for full-disk encryption or an emerging category of "policy-based" encryption doesn't really matter from a compliance standpoint (although better security generally means better defense against lawsuits).

Portable Data Protection Options PDF

But encryption isn't the only option for protecting both laptops and an increasingly loaded bevy of handheld devices, from PDAs to supercharged mobile phones. Companies also have to weigh where a password is enough and if not, assess what authentication method to use to access the device. And they also can consider software that either deletes sensitive information or traces the device if it is indeed stolen. Many of the options in this last category are even built into existing products. Purdue, for instance, has taken advantage of a feature built into the popular BlackBerry that allows the device to be remotely reset if it's lost or stolen.

To help you sort out all the options, we talked to David Friedlander, a senior analyst at Forrester Research, and Eric Maiwald, a senior analyst at the Burton Group. Then we did a whole lot of legwork and a little bit of shopping. The results are presented in our first-ever buyer's guide to securing portable devices. [We've made the guide available as a one-page PDF.] We even threw in a couple of theft prevention options, although nothing takes the place of educating users about protecting their portables. (Please note that prices are approximate, and vendor lists are not meant to be all-inclusive.)

CSO

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors