Randy George


Upcoming Events

Interop NY
Oct. 1-5

Interop is the only event to give you a comprehensive and unbiased understanding of all the latest innovations-including cloud computing, virtualization, security, mobility and data center advances-that help position your company for growth.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Tags: , , , , , , , , , , , ,

Channel: Data Protection

See more from this blogger

USB Thumb Drives Are A Convenience, But Also A Major Threat

If you're like me, then you have a drawer full of USB thumb drives that you've collected from vendors over the years. Whenever I'm in a rush, I pop one out, copy some data to it, and transport it to its destination. Then what do I do? I usually leave it around like I do pens, sticky notes, and CD-ROM's. And while I encourage you to steal my sticky notes, I care a lot about protecting my thumb drives from theft. If you're not taking seriously the threat that removable devices pose to your network, now's the time to pay attention. Vendors and enterprise IT shops have certainly taken notice of the security risk that USB thumb drives pose. A ton of software and encryption solutions have been developed to address the problem. Further driving the need for solutions in this space are new regulatory standards for the exchange and protection of sensitive electronic information.

It's a well-known trick in the security auditing trade that dropping USB thumb drives in the parking lot of a company you want to crack is an easy way to infiltrate a network. Nine times out of 10, the unsuspecting employee will be curious about the contents of the thumb drive. Once plugged in, any viruses, malware, or scripts injected onto the drive are free to spread and compromise network security.

While viruses are right at the top of the list of reasons to disallow the use of USB thumb drives in the enterprise, data leakage is the top cause for concern for most. Fortunately, there are plenty of solutions to the problem out there, both cheap and expensive. If you're running XP, you can apply a registry hack to disable USB plug-and-play devices by brute force. That's certainly not a friendly solution, but it is a solution. Vista gives you a few more options in the way of USB device enforcement, but none rely on user credentials, which is where the more expensive enterprise offerings pickup.

ControlGuard, GuardianEdge, and Sanctuary Device Control from Lumension Security are three examples of enterprise solutions that provide protection from data leakage and malware from removable devices. More important for the security administrator, detailed logging, auditing, and regulatory compliance features are built into many of these offerings. End to end features that protect and report are enough to help CIO's sleep a little more soundly at night. And while these enterprise offerings aren'ot cheap, what's the cost of not having them?

Know of any highly effective, low-cost solutions in this space? Post a comment here and let me know about them.

Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

Research and Reports

Storage Virtualization Guide
May 2012

Network Computing: May 2012

TechWeb Careers