Disk Encryption and File Encryption
Home > Ask the Security Experts > Platform Security Questions & Answers > Should whole disk encryption products be used with data backup software?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Should whole disk encryption products be used with data backup software?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 30 January 2008
Is it best to use whole-disk encryption products as well as data backup software for disaster recovery at the same time? Or should my organization choose one or the other?

>
EXPERT RESPONSE
Disk encryption and disk backup play two distinct roles and should be considered in the context of overall system security, be it one laptop or a whole enterprise network. System security is all about maintaining the confidentiality, integrity and availability of the system and the data entrusted to it.

Therefore, using encryption to protect data from prying eyes is not the same as securing the information. If someone steals the encrypted disk, you can derive a valuable dose of comfort from knowing that the thief will have a hard time accessing the contents. If those contents include personally identifiable information (PII) pertaining to thousands of customers, that encryption will help ensure the confidentiality and integrity that your customers were promised when you requested the data from them.

So the simple answer to the question is affirmative. Backup is a must, and whole-disk encryption should be considered as well, but of the two, backup is more critical. Where the two mechanisms come together is encrypted backup, which is definitely something to consider if you are talking about adequately securing sensitive data. The combined approach allows programs to encrypt the data as they write it to the backup media, be it tape, removable hard drive or network server.

Regardless, backup media should be stored securely and separately. In other words, there should be at least one backup safely stored in a different location from the original. Imagine going to the trouble of making regular backups, but then storing them all in the same office as the drives holding the original data. If the office is burglarized, everything may be lost. It would be little consolation to know that the thief can't get at the data because it is encrypted; it would be a huge relief to know that there were a copy of the data in the company's safety deposit box at the bank.

More information:

  • Learn about the whole-disk encryption benefits of Vista's BitLocker.
  • A SearchSecurity.com reader asks expert Ed Skoudis, "Are encryption products better than self-destructing data?"


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Platform Security
    Is attack code valuable for vulnerabilities or just a publicity stunt?
    Will the features of Windows Vista SP1 encourage wider adoption of the OS?
    Is a Master Boot Record (MBR) rootkit completely invisible to the OS?
    Are open recursive DNS servers inherently insecure?
    Which operating system can best secure an FTP site?
    Is desktop virtualization a realistic enterprise option?
    Does FTPS encrypt data packets at the hardware or software level?
    Should disks be encrypted at the hardware level?
    Is Triple DES a more secure encryption scheme than DUKPT?
    Will a platform-as-a-service (PaaS) environment put data at risk?

    Disk Encryption and File Encryption
    Growing Mac use prompts call for better security
    Websense, Reconnex top Forrester ranking of DLP vendors
    Embedded Security Safeguards Laptops
    Does FTPS encrypt data packets at the hardware or software level?
    Should disks be encrypted at the hardware level?
    Is Triple DES a more secure encryption scheme than DUKPT?
    Windows BitLocker: Enabling disk encryption for data protection
    NAC, disk encryption gaining attention, survey shows
    Symantec fills gap with whole disk storage encryption
    Case Study: Company Deploys Full-Disk Encryption on All Laptops

    Data Backup
    Will one failed drive corrupt the rest of a RAID-5 array?
    The Craft of System Security
    Can confidential data be accessed once it is deleted for free space?
    Examining DoD-level secure erasure guidelines
    What is the relationship between open port range and overall security risk?
    Compliance, data breaches heighten database security needs
    Are encryption products better than self-destructing data?
    What is a logic bomb?
    What should be done with a RAID-5 array's failed drives?
    Database authentication, encryption getting priority in some businesses

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Advanced Encryption Standard  (SearchSecurity.com)
    data key  (SearchSecurity.com)
    Encrypting File System  (SearchSecurity.com)
    Escrowed Encryption Standard  (SearchSecurity.com)
    International Data Encryption Algorithm  (SearchSecurity.com)
    network encryption  (SearchSecurity.com)
    output feedback  (SearchSecurity.com)
    quantum cryptography  (SearchSecurity.com)
    Quiz: Cryptography  (SearchSecurity.com)
    Rijndael  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts