Senforce takes care of endpoint security

Opinion
Sep 11, 20064 mins

* The Senforce Endpoint Security Suite

As if security officers don’t have enough to worry about, consider this ad for a monitoring tool that we just came across.

SnoopStick is a USB flash drive type device that allows you to monitor what your kids, employees, or anyone using your computer is doing while on the Internet. And, you can monitor them live, in real time, from anywhere in the world.” The ad continues: “Simply plug the SnoopStick into the computer you want to monitor. Then run the setup program to install the SnoopStick monitoring components on the computer. The whole process takes less than 60 seconds. The SnoopStick monitoring components are completely hidden, and there are no telltale signs that the computer is being monitored.” And it’s only $59.95.

For just 60 bucks and a minute or two of time, anyone with physical access to your company’s computers can compromise security. If that doesn’t make you nervous, then I don’t know what will.

With the recent rise in the popularity of removable media, wireless network access, mobility in general, and now gadgets like the SnoopStick, it’s time to take control of your enterprise endpoint security.

I’ve been talking lately to Senforce Technologies about the endpoint security they offer, and this company should be on your radar. The Senforce Endpoint Security Suite uses the approach of distributed enforcement via an agent on the desktop with a centralized console for administration and reporting. This takes the responsibility of making security decisions out of the users’ hands and into the hands of a security administrator who works from a set of enterprise policies.

Observing that notebook PCs are now outselling deskbound devices, Senforce has a special emphasis on protecting mobile computers. The agent that is placed on an endpoint device is “location aware,” and the security policies that are enforced are dependent on the device’s current environment.

For instance, let’s say an employee has a notebook PC that he uses in the office, at home and on the road. The PC essentially has three policy profiles – one for each of his work locations and the unique threats they present. The security agent on the PC recognizes which profile should be enforced at any given time based on an IP address, how the device connects to the network and other settings. As the user moves from one location to another, the appropriate security profile takes over.

The profile determines what the user can do with his device. For example, you might determine that it is OK for this employee to access customer information when he is physically in the office, but not when he is working at home or on the road. And when he is on the road, you can disable access to unrecognized and unsecured public Wi-Fi networks. The security policy could even force the employee to use a secure VPN for enterprise access.

Policies, of course, can be set by groups or individual users. Senforce calls it “degrees of freedom.” They recommend you start with simple policies and get comfortable with them, and then refine them as needed, setting the granularity of access for specific users.

Suppose you have a sensitive project, like a prospective acquisition. You can allow members of the M&A team to access information about the project, but disallow them from copying any of the data onto USB thumb drives. (If thumb drives make you nervous – review the intro paragraph above – you can disable all of them within the company and then re-enable only specific drives.)

Senforce’s security policies are completely transparent to the end user, even as he moves from one location profile to another. What’s more, the policies are deployed at the kernel level of the computer, so there is little chance that even a sophisticated user can circumvent them.

I mentioned central administration of the policies. Senforce has its own console, and in addition, Senforce and Altiris recently announced a partnership that allows you to develop, deploy and enforce endpoint security policies from the Altiris management architecture.

Network World has recognized Senforce as a security innovator, giving praise to the Client Location Assurance Service, “which provides crypto-based assurance that a system resides on a known, trusted network and is not being spoofed. This innovation gives users and administrators reasonable assurance that systems are on a trusted network.”

If you aren’t doing enough to address endpoint security with all your computing devices, now is the time, before your company provides the next blaring headline about a security breach and loss of important data. Something as vital as your whole customer database could be lifted right out from under your nose, and you might never know it.