Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Stolen data? No biggie

Storage encryption puts IT execs at ease about the threat of identity theft.
By Sandra Gittlen , Network World , 06/27/2005
  • Share/Email
  • Tweet This
  • Comment
  • Print

IT executives hoping to avoid brand-damaging thefts of stored data like those experienced by AOL, Bank of America and Citigroup are turning to an age-old security strategy: encryption.

Take Vincent Fusca. As operations director at the Center for Evaluative Clinical Sciences at Dartmouth College in Hanover, N.H., he is responsible for 7T bytes of Medicare patient information tied to more than $5 million in research grants.

"Under HIPAA compliance, we need to make sure that we have the most secure means possible to hold and utilize the data in support of research," Fusca says. "If I lost this data, I'd be roadkill."

As companies develop new data center architectures, they're increasingly focusing on secured storage. "Storage people have been so myopic on performance and availability that security hasn't been an issue. But they're starting to pay more attention," says Jon Oltsik, senior analyst for information security at Enterprise Strategy Group.

At Dartmouth, Fusca employs an encryption appliance from Decru to secure the information on his storage servers and back-up tapes. Such appliances, also available from vendors such as Kasten Chase Applied Research, NeoScale Systems and Vormetric, sit on the network, encrypting and decrypting data as it passes through from hosts and enterprise-wide storage resources. Fusca uses Decru's DataFort to convert raw files from Medicare into encrypted data silos for use by the center's researchers, analysts and programmers.

In the past, IT pros who wanted to secure stored data would have had to use software, says Andreas Antonopoulos, senior vice president at Nemertes Research. But that approach caused unacceptable performance slowdowns.

"Appliances use sophisticated ASICs and can achieve much better performance by doing all the encryption in the hardware," he says.

Limited encryption

Encrypting stored data - especially backups traveling offsite and out of an IT executive's physical control - is a good idea, Antonopoulos says. He points especially to companies that fall under compliance measures, such as California SB 1386, which specifies that state employees and customers must be notified within 30 days if a data breach involves information about them. "Encrypted data is exempt from this. Right there, you can save your brand," he says.

While the temptation might be to encrypt all stored data, what's best is to be selective about what data needs protecting, experts say. Dale Pickford, vice president at Ocwen Financial, a mortgage processor in West Palm Beach, Fla., says he only encrypts about 200T bytes, or 5%, of his stored data. Encrypting everything would be too expensive and time-consuming, he adds.

First encrypt external-facing data that contains potential identity theft material. "Name, address, Social Security Number, date of birth - basically any combination that lets you steal someone's identity," Pickford says.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Partner Content

Gartner 2009 Magic Quadrant for Job Scheduling

Gartner has positioned BMC CONTROL-M in the Leaders Quadrant of their "2009 Magic Quadrant for Job Scheduling." The report assesses the ability to execute and completeness of vision of key vendors in the marketplace. Read a full copy today, courtesy of BMC Software.

Download whitepaper

Dell's SMART Approach to Workload Automation

Read a compelling case study by EMA, Inc. to learn how Dell uses BMC CONTROL-M to cut cost and increase productivity with workload automation.

Download whitepaper

Workload Automation Cost Savings 2 Minute Video

A major computer manufacturer uses BMC CONTROL-M and just four people to schedule and run over 85,000 jobs every month. By switching to BMC CONTROL-M, they more than quadrupled the workload without adding a single staff member.  See how in this 2-minute video overview.

Go to video

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed