* The SanDisk Enterprise Division addresses the weaknesses of USB flash drives
What would happen if one of your coworkers lost a USB flash drive containing extremely sensitive customer information? Would it cause panic because of the potential for data exposure and massive fines and costs for restitution? Or would you relax knowing that the data is encrypted, the flash drive is password-protected, and you have the ability to terminate the drive if it’s ever used again? If it’s the former case, read on to see how to move from “panicked” to “relaxed.”
Imagine yourself in this position. It’s Monday morning, and your task is to go to your lead executive to let him know that an ambitious employee who wanted to get some work done over the weekend just reported that her USB flash drive was either lost or stolen from her desk. The drive contains downloaded medical and financial records for 1,200 patients with HIV, AIDS and other medical conditions. The data stored on the drive is not password-protected or encrypted and includes the patients’ names, medical record numbers, billing codes, the facilities where the office visits occurred and other billing information. It also included the patients’ Medicaid or Medicare numbers, which can indicate their Social Security numbers or those of their spouses.
What a way to start the week, right?
The unfortunate thing is that this scenario really happened. In July 2008, an administrator at the Harris County (Texas) Hospital District admitted losing the USB drive with all that sensitive information. She simply wanted to catch up on her work at home over the weekend, and now the county department has a major data breach – as well as HIPAA violations – on its hands.
Could something like this happen in your office? Very likely, yes. In recent years, USB flash drives have proliferated; their cost and convenience make them extremely popular with office workers. You, yourself, probably have a handful of them in your desk drawer. I do.
SanDisk Corporation, a leading maker of those popular little USB flash drives, commissioned a study on the risks of unsecured flash drives. The study revealed some not-so-surprising insight:
* 77% of corporate end users have used personal USB flash drives for work-related purposes.
* End users report the types of data most likely to be copied to a personal flash drive include customer data, financial information, business plans, employee data, marketing plans, intellectual property, and source code.
* 44% of corporate end users indicate their company does not have a policy that forbids copying corporate data onto a personal USB flash drive.
* 67% of corporate IT managers are implementing or have implemented policies as a result of a data/security breach in their organization.
It’s no secret that USB flash drives are a weak link in the data security chain. The SanDisk Enterprise Division is addressing that weakness by working with a variety of partners in the SanDisk Enterprise Solutions Technology Alliance (SESTA).
Formed in September 2007, SESTA now includes at least 25 leading security vendors, including CheckPoint Software, McAfee, RSA, VeriSign and a host of other companies. The purpose of SESTA is to develop solutions that close the backdoor that leaves enterprises vulnerable to risk and non-compliance. The result is that SanDisk now offers flash drive products that offer security at multiple tiers, including hardware-based data encryption, password protection, anti-malware detection, strong authentication, and central management.
SanDisk has a range of enterprise products with security solutions from the SESTA partners built into the USB flash drive. A company can select the product(s) that best address their organizational risks:
* SanDisk Cruzer Enterprise is a password protected USB drive that imposes mandatory access control on all files, storing them in a hardware-encrypted, password-protected partition. This secures all stored data in the event of drive loss or theft.
* SanDisk Cruzer Enterprise Secure USB with McAfee Malware Protection also includes automatic, device-resident malware scanning, which helps ensure that the USB flash drives and the corporate networks with which they connect are free of malicious code. This device leverages the capabilities of the McAfee scan engine to automatically detect and prevent USB-borne threats.
* SanDisk Cruzer Enterprise FIPS Edition includes FIPS 140-2 level 2 certification for encryption. Rather than rely upon users to secure files, this device imposes mandatory access control on all files, storing them in a secure partition that implements the strongest 256-bit hardware-based AES encryption.
* Central Management and Control (CMC) is a management console for the Cruzer Enterprise flash drives. CMC allows for tasks such as initial user-deployment, password recovery, data backup and drive termination. CMC provides continuous enforcement of company policy, tracking and monitoring activity beyond the corporate network.
* SanDisk Cruzer Professional is a USB flash drive that incorporates security measures that don’t require management through the Central Management and Control console. Features include strong hardware-based encryption (256-bit AES) independent of operating system; password-protected area for sensitive files; and device lockdown mode after a preset number of incorrect password attempts.
These USB devices provide a secure alternative to completing shutting down the use of USB drives within a company. They give employees the ability to transport data, but in a safe and controlled way. Then if a flash drive is lost or stolen, there’s little concern that the data can be accessed.




