* OMB memo on data safeguards
Losses of laptop computers with unencrypted hard drives continue to be reported week after week. On Aug. 14, the U.S. Department of Transportation admitted to laptop losses for the second time in a week.
Partly in response to the loss of control over confidential data on government computers, Clay Johnson III, deputy director for management of the Office of Management and Budget (OMB) issued a memorandum on June 23, recommending the following safeguards for all federal government agencies (quoting exactly):
“The National Institute of Standards and Technology (NIST) provided a checklist for protection of remote information… The intent of implementing the checklist is to compensate for the lack of physical security controls when information is removed from, or accessed from outside the agency location. In addition to using the NIST checklist, I am recommending all departments and agencies take the following actions:
“1. Encrypt all data on mobile computers/devices which carry agency data unless the data is determined to be non-sensitive, in writing, by your Deputy Secretary or an individual he/she may designate in writing;
“2. Allow remote access only with two-factor authentication where one of the factors is provided by a device separate from the computer gaining access;
“3. Use a ‘time-out’ function for remote access and mobile devices requiring user re-authentication after 30 minutes inactivity; and
“4. Log all computer-readable data extracts from databases holding sensitive information and verify each extract including sensitive data has been erased within 90 days or its use is still required.”
The document includes an extensive list of recommendations which referred to specific special publications (SP) from the National Institute of Standards and Technology (NIST). The specific references are cryptic; for example, “Related SP 800-53 controls and associated SP 800-53A assessment procedures: AC-1 ACCESS CONTROL POLICY AND PROCEDURES SP 800-53A: AC-1.1, AC-1.2, AC-1.3, AC-1.4 (for high impact add: AC-1.5, AC-1.6, AC-1.7).”
The San Francisco-based security company GuardianEdge Technologies has prepared a 45-page guidebook (free, but registration required) that helps readers interpret these cryptic references; e.g., “AC-1.1: Examine organizational records or documents to determine if access control policy and procedures: (i) exist; (ii) are documented; (iii) are disseminated to appropriate elements within the organization; (iv) are periodically reviewed by responsible parties within the organization; and (v) are updated, when organizational review indicates updates are required.”
On a related note, GuardianEdge products were recently selected by the Veterans Administration as disk encryption tools to implement the OMB directive.
I have recommended to my colleagues in the Norwich University IT department that we study the OMB memorandum and the GuardianEdge guidebook as a basis for implementing university-wide disk encryption policies. I think readers would also do well to study these documents.
I am grateful to Timothy J. Polakowski of McGrath/Power Public Relations for bringing these documents to my attention on behalf of GuardianEdge. However, I have no involvement of any kind with that company and have not studied their products. References to their products do not constitute an endorsement.




