Upcoming Events

Where the Cloud Touches Down: Simplifying Data Center Infrastructure Management

Thursday, July 25, 2013
10:00 AM PT/1:00 PM ET

In most data centers, DCIM rests on a shaky foundation of manual record keeping and scattered documentation. OpManager replaces data center documentation with a single repository for data, QRCodes for asset tracking, accurate 3D mapping of asset locations, and a configuration management database (CMDB). In this webcast, sponsored by ManageEngine, you will see how a real-world datacenter mapping stored in racktables gets imported into OpManager, which then provides a 3D visualization of where assets actually are. You'll also see how the QR Code generator helps you make the link between real assets and the monitoring world, and how the layered CMDB provides a single point of view for all your configuration data.

Register Now!

A Network Computing Webinar:
SDN First Steps

Thursday, August 8, 2013
11:00 AM PT / 2:00 PM ET

This webinar will help attendees understand the overall concept of SDN and its benefits, describe the different conceptual approaches to SDN, and examine the various technologies, both proprietary and open source, that are emerging. It will also help users decide whether SDN makes sense in their environment, and outline the first steps IT can take for testing SDN technologies.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Wave Embassy Trusted Drive Manager Simplifies Encrypted Drive Management

We tested TDM on Embassy Trust Suite and ERAS using a pair of Dell Lattitude E6400s. One had a Seagate Momentus 160GB, 7200 RPM hard disk and the other had a Samsung PB22-JS3 Full Disk Encryption (FDE) solid state drive. Both laptops were part of the domain, but only one drive was managed by ERAS. The other was managed with Wave's Embassy Security Center locally so we could get a feel for local administration. In an enterprise environment, you definitely want ERAS to make it easier to support multiple laptops.

Unlike software disk encryption which either encrypts the drive or not, encrypting hard drives are always encrypting and decrypting the data written to and read from the drive. A drive becomes protected when user credentials--an account and password--is added to the drive. The user credentials encrypt the drive Media Encryption Key. A successful login to the drive decrypts the Media Encryption Key, granting access to the drive. The Media Encryption Key never leaves the drive. Multiple user accounts can be assigned to the drive, and each account will have its own copy of the Media Encryption Key encrypted with the user password. If you want to wipe the drive, you can have ERAS generate a new drive Media Encryption Key. NIST is considering making a Media Encryption Key change equivalent to a level-4 wipe, which requires 7 overwrite passes of a drive.

The price premium for an encrypting drive isn't as much as you might think. For example, a Seagate Momentus 160GB, 7200 RPM has a street price of approximately $88, while a similarly sized non-encrypting drive are less. The price difference between encrypting SSDs is difficult to nail down because Samsung's FDE SSD is an OEM product. A Web search showed a range of  between $600 and $700 for the Samsung FDE and nonFDE 256GB drives. However, you don't need encrypting drives on all your laptops--just the ones carrying sensitive data.

ERAS is a Microsoft Management Console (MMC) plug-in. The computers in the domain show up in the Computers tab, which displays the computers' status such as drive protection.. There is also an extensive audit log that is sent to Microsoft's event log to track administrative actions . ERAS manages encrypting drives and the Trusted Platform Module (TPM) if it is installed and enabled. Management of trusted drives is fairly hands-off once the drives have been initialized and users have been assigned to them. Multiple users can be assigned to a single laptop, so that a laptop can be shared among many users, or to retain administrative privileges.

Once a trusted drive is managed by ERAS, local management is blocked. A drive administrator can view the trusted drive options, but changes can only be made from ERAS. This feature centralizes control and logging at ERAS and prevents administrators or users that have direct access to a machine from changing trusted drive settings, potentially irretrievably locking a drive. Centralized management also means that computers managed by ERAS must be connected to the ERAS server for changes to take immediate effect. If a computer is not connected, such as a laptop that is out of the office, the configuration changes are queued until the computer connects to ERAS.


Page: « Previous Page | 1 2 | 3  | Next Page »


Related Reading


More Insights


Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | Please read our commenting policy.
 
Vendor Comparisons
Network Computing’s Vendor Comparisons provide extensive details on products and services, including downloadable feature matrices. Our categories include:

WAN Security Reports

Research and Reports

August 2013
Network Computing: August 2013



TechWeb Careers