Home > Ask the Security Experts > Platform Security Questions & Answers > Should full disk encryption be used to prevent data loss?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Should full disk encryption be used to prevent data loss?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 15 December 2006
Given that so much important information is found on company laptops, should a computer's entire hard drive be encrypted? What are the pros and cons?


BROWSE BY TAG
Platform Security,   Enterprise Data Protection,   Disk Encryption and File Encryption,   Identity Theft and Data Security Breaches,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Platform Security
What are the security risks of Windows Vista RSS functionality?
How to harden Linux operating systems
What are the key provisions of Massachusetts Executive Order 412?
A simple substitution cipher vs. one-time pad software
When should a virtual patch be used?
What is the best operating system for an FTP server implementation?
Are encrypted, self-deleting USB storage drives worth the investment?
Can read/write access policies be put on a SAN server?
Is it more secure to have a mainframe or a collection of servers?
Should open source disk-encryption software be used?

Disk Encryption and File Encryption
Database monitoring, encryption vital in tight economy, Forrester says
Sophos integrates encryption into endpoint security
Cryptography for the rest of us
Encryption in data management should never be ignored, expert says
Security budget issues to resonate at RSA Conference
Portable security storage device could replace OTP devices
Mass. officials explain new data protection regulations
A simple substitution cipher vs. one-time pad software
Are encrypted, self-deleting USB storage drives worth the investment?
Massachusetts data protection, encryption law extended

Identity Theft and Data Security Breaches
TJX to pay $9.75 million for data breach investigations
Man pleads guilty in online banking hacking scam
White House cybersecurity czar faces major hurdles
Heartland breach cost $12.6 million, CEO says
An inside look at security log management forensics investigations
LexisNexis investigates breach, notifies thousands
Senators hear call for federal cybersecurity restructuring
Former Federal Reserve Bank employee arrested
Attackers cash in on fundamental data handling mistakes, Verizon finds
Courts turn aside data breach suits

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Advanced Encryption Standard  (SearchSecurity.com)
data key  (SearchSecurity.com)
Encrypting File System  (SearchSecurity.com)
Escrowed Encryption Standard  (SearchSecurity.com)
International Data Encryption Algorithm  (SearchSecurity.com)
network encryption  (SearchSecurity.com)
output feedback  (SearchSecurity.com)
quantum cryptography  (SearchSecurity.com)
Quiz: Cryptography  (SearchSecurity.com)
Rijndael  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Stories of lost or stolen laptops containing sensitive information appear almost weekly in the news, and according to a Ponemon Institute survey done in August 2006, around four out of five organizations have suffered data loss in this fashion. I would consider controlling what data can be downloaded to a company laptop in the first place, but statistics certainly support more widespread use of data or hard drive encryption.

So why don't we encrypt our data as a matter of course? Well it's probably because of the impact on performance, plus the required increase in system administration and user support. Full-disk encryption (FDE) is a process that encrypts everything on a disk without user action. This includes the operating system, swap file and any temporary files. These last two can often leak important confidential data to a hacker. FDE also provides support for pre-boot authentication. It's an effective technique, but encryption can double data access times, particularly when virtual memory is being heavily accessed.

Another, more significant problem, though, is encryption key and password management. Any encryption system is only as safe as the encryption keys. With FDE, only one key is used to encrypt the entire disk. Usually keys are stored on the local system, and their sole protection is typically the user's password or passphrase. And we all know how weak they can be! Disk encryption therefore requires policies that enforce strong passwords and can handle forgotten passwords, encryption key backup processes and employee termination.

Despite these disadvantages, I think FDE is fast becoming an essential security requirement for any organization that holds sensitive data. Data loss can be crippling both financially and legally, and protecting data with a well-implemented FDE policy will prevent many of these problems. File encryption such as Microsoft's Windows EFS (Encrypting File System) is a start, but EFS doesn't encrypt all of the data saved on the hard disk. Also, file encryption is nowhere near as efficient as drive encryption.

There are plenty of new products that will make FDE a more practical solution. Windows Vista Enterprise and Ultimate editions, for example, include BitLocker full volume encryption (FVE). It encrypts the partition on which Vista is installed, and it does so on a sector basis rather than by files. This arrangement protects all data, including that in the paging file, hibernation file and all system files. Other partitions can only be protected using EFS, but at least the EFS encryption keys are located on the OS partition. On the hardware side, Seagate is about to ship a hard drive that includes a special encryption chip that will make its data impossible for anyone to read -- or even boot up its PC -- without some form of authentication. (I'm a fan of using hardware tokens to reduce password management overhead, but it's an additional cost to consider.) Thankfully, Seagate is also working to develop an enterprise password management system that works with the drives.

More information:

  • Learn the best practices for encryption key management.
  • Implement database encryption, while saving money in the process.



  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts