Data Security in a Mobile World Emmitt Wells – Getronics
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 3 Hitting Close to Home If you think mobile security isn’t a real subject, just consider the possibility that there is someone out there right now with your name, , phone number, and birth date and more stored on a digital device that was just left in a taxi cab – not a comforting thought.
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 4 View of Endpoint Security…
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 5 All Sectors –SOX, Combined Code, Companies Bill, IAS –Privacy, Data Protection, Human Rights Finance Sector –Basel II, FSA, SEC Act 17a-3/4, NASD Rules 3010/3110 Retail Sector –Payment Card Industry (PCI) Security Standard Health Sector –HIPAA Interception legislation –RIPA, European Data Retention Directive Local legislation with Global consequences –Californian Law SB 1386 Compliance Demands are Mounting
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 6 Securing Data in Motion
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 7 Ensuring Data Integrity
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 8 Data Theft
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 9 Policy Establish
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 10 Technology Available Endpoint Products –Anti-virus, anti-spam, Message Cleaning, HIDS for the desktop Controlling Access –Identity Management and Authentication External Protection –Firewalls and NIDS Data Protection –Policy Enforcement Tools Backup and Retrieval –Secure Archival Stolen Equipment –Data low-jack
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 11 What if I do nothing? “Gartner estimates cleanup costs for any data loss to be $90 per customer record when you calculate notification, legal expenses, and the damage done to a corporate brand." = = +
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 12 How do I convince my executives of the need? Discuss Technology Discuss Business Impact
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 13 Balanced Security
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 14 Policy –Define rules, promote best practices and minimize risks Technology –Enforce policies, detect violations of policy, and deliver evidence of compliance with corporate policy and regulatory requirements Education –Equip employees to recognize potential sources of risk and to safeguard information and transactions in hostile environments Management –Setup reactive and proactive management to help measure how your endpoints are performing against the policy you have established Requirements for Mobile Endpoint Security
September 10-12, 2007 Los Angeles Convention Center Los Angeles, California 15 Keep it Simple "Aye sir, the more they over-tech the plumbing, the easier it is to stop up the drain." – Mr. Scot, Star Trek III: The Search For Spock
Thank you