Home > Midmarket CIO Tips > Security for the midmarket > Laptop theft easily preventable while on the road
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

Laptop theft easily preventable while on the road


Joel Dubin, CISSP, Contributor
04.07.2008
Rating: -4.33- (out of 5)


Technology news and tips for Midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


As the technology for mobile computing becomes more efficient, easier to access and less expensive, the number of workers working remotely is increasing rapidly. Unfortunately, so are the security risks.

Midmarket companies without the resources for complicated and expensive network access control systems or endpoint security products are particularly vulnerable to breaches from lost or stolen laptops. And as we hear every day now in the news, stolen or lost laptops with confidential customer information or sensitive company data can cause incalculable damage to a company of any size.

Fortunately, there are solutions that don't require expensive hardware or software and can protect both laptops and the networks to which they connect. By using an established set of policies and procedures combined with some reasonably priced and easy-to-deploy products, there is no longer an excuse for sloppy mobile computing security practices.

Two-pronged approach to security

For midsized companies, there's a two-pronged approach to securing laptops that I think works best.

More on IT management
Desk phone inching off desk, toward trash

Wireless computing: What won't happen in 2008
First is the low-tech approach. This involves teaching the basics of laptop safety -- never leave your laptop unattended, use privacy filters to prevent shoulder surfers and other wandering eyes from stealing user IDs and passwords, and be aware of your surroundings. A little bit of education goes a long way. Put this information in a PowerPoint presentation or a company policy and make sure mobile workers sit through a review of this policy once a year as a condition of employment.

While laptop theft at airports is rampant, there is just as much risk in hotel rooms and rental cars. In hotels, it's probably best to take a laptop with you rather than leave it in the room unattended. As for rental cars, laptops shouldn't be left on car seats where they can be seen during appointments or visits to client sites. Make it a policy to lock a laptop in the trunk. Better yet, lock it in the trunk via cable to the spare tire.

When traveling, especially through airports, have employees carry laptops in briefcases, not in easily identifiable laptop carrying cases. Briefcases, carrying cases and the laptops themselves shouldn't have company markings, corporate logos or other features making them stand out. Your marketing department might not be happy with the lack of public exposure of the company's brand, but it'll be another step to keeping laptops out of the wrong hands. Laptops, like employees, should blend in the crowd as much as possible when on the road.

My second approach is using security tools, such as antivirus protection, firewalls and virtual private network (VPN) software. The first rule is that anyone working remotely can use only a company-issued laptop both out of the office and when connecting to the network.

Every company laptop should have a standard build reviewed and approved by your IT department or staff to ensure it meets information security standards. That means it should have updated antivirus protection, personal firewalls and VPN software for communicating back to the network.

As the CIO you should have a complete inventory of all laptops in use at the company. At the very least, have a list of makes, models, serial numbers, dates of purchase, the employee to whom each laptop was given and the date of issuance. If possible, barcode every laptop before it goes out the door, preferably with something tamperproof or even engraved on the case. You can't secure what you don't know you have, and a full accounting of where all your laptops are and who has them is vital to implementing any security controls.

Employees using laptops outside the office, whether at home or on the road, should be allowed to access the company network by only mobile VPN. If an IPSec VPN is too cumbersome for a smaller company, consider a Secure Sockets Layer VPN, which is just a Web-based VPN without some of the extra client software and hardware of its heavier-weight IPSec counterparts.

VPN access also protects the network from laptop users connecting from wireless access points, which are now common in airports and hotels. Public wireless hotspots are notoriously insecure -- and frequently unencrypted -- but a VPN creates a secure encrypted tunnel that lowers the risk tremendously.

Encryption is best defense

Now, despite all these controls, be forewarned: Laptops will get stolen. You can bet on it. So the best way to protect your company's data is full-disk encryption (FDE). With FDE, all the data on the laptop is constantly encrypted behind the scenes while the user is working. When the user shuts down, the entire hard drive is encrypted. When the user boots up again, he or she is prompted for a password that unlocks the machine. To a laptop thief without the password, the data on the disk will appear as gibberish.

Make it a policy to lock a laptop in the trunk. Better yet, lock it in the trunk via cable to
the spare tire.

A market leader in FDE is SafeBoot Technology N.V., which is now part of McAfee Inc. SafeBoot is geared to companies of all sizes and comes complete with management tools for centralized control of laptops by your IT staff. Another commercial product offering centralized management is PGP Desktop Professional.

Two popular free tools, similar to SafeBoot but lighter weight, are TrueCrypt and FreeOTFE. Both provide either full or partial disk encryption but don't offer the same centralized management options of a commercial product, like SafeBoot or PGP. But if you have a limited number of laptops to manage, free encryption tools might be a good option.

A policy for policies

All of these aforementioned suggestions should be enshrined in your company's IT security policy. Though policies are only as strong as the paper they're written on, they at least are a guide to what's expected of employees if a question comes up. And written policies, at least, rather than verbal directives, can (and should) be enforced.

Finally, have an incident response plan in case a laptop is lost or stolen. Have a number employees can call 24/7 to report a missing laptop. There should be an on-call rotation schedule with someone able to take action, to notify the police if necessary, mark the laptop as missing in the inventory and, if possible, wipe or disable the laptop remotely.

Joel Dubin, CISSP, is an independent computer security consultant. He is a Microsoft MVP specializing in Web and application security, and is the author of The Little Black Book of Computer Security, available from Amazon.com. He has a regular radio show on computer security on WIIT in Chicago and runs The IT Security Guy blog at www.theitsecurityguy.com.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Security for the midmarket
Risk assessment frameworks easy to employ
Compliance: Don't let your guard down
Single sign-on: Sensible security on scale
Information security requires organized teams
How to choose a DR service provider
Security on a midmarket budget
Security's crystal ball for 2008
Security outlook challenging for SMBs in 2008
SMB security reporting: The devil is in the details
Disaster recovery drill: Do you know how to cover your assets?

Information security management for the midmarket
San Francisco network lockup justifies CIO fears
A cloud computing takeover? Google thinks so
An IT spring cleaning for CIOs
Single sign-on: Sensible security on scale
Spyware defense for the midmarket
Federal breach notification stuck in Congress
Anti-spam tricks for the midmarket toolbox (expert podcast)
Pre-emptive strategy best approach to breach notification
CIOs under fire and in front of the camera
Compliance-burdened CIOs turning to security management tools

Data privacy for the midmarket
Database security: Limiting access is key
Federal breach notification stuck in Congress
Pre-emptive strategy best approach to breach notification
CIOs under fire and in front of the camera
Personal health records latest concern for CIOs
Computer recycling: Dangers for even the well intentioned
Phishing attacks slam midmarket
Data destruction made simple and cheap
Editor's Letter
Privacy: The Midmarket CIO Career Killer?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2007 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts