Home > Midmarket CIO Tips > Security for the midmarket > Laptop security best practices
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

Laptop security best practices


Joel Dubin, CISSP, Contributor
06.11.2007
Rating: -3.80- (out of 5)


Technology news and tips for midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


More employees with more laptops can mean greater exposure of your network to roaming security threats. And, in a worst-case scenario, a stolen laptop with sensitive customer data or proprietary company information can also expose the company to liabilities, legal or otherwise. Lost customer data can lead to identity theft and open the company to lawsuits. Lost proprietary information can damage the company's competitive edge, if not its business altogether.

Large organizations have sophisticated network defenses and firewalls to block malware from compromised laptops. For outbound threats, they may also employ complex content control systems to prevent the loss of customer data or company information. Not so for small and medium-sized businesses (SMBs), which may operate simple firewall networks on a shoestring and don't have the cash to spend on expensive content filtering systems and software.

But there are solutions for SMBs that won't break the budget and involve little or no overhead. Many of these solutions rely on simple procedures and best practices that don't require bulking up stretched-thin IT departments or hiring a dedicated information security team.

There are three parts to laptop security: physical security, administrative access and technical controls.

Encryption is vital for making sure data on the laptop doesn't fall into the wrong hands, in case the laptop is lost or stolen. Full disk encryption makes the laptop unusable to anyone who doesn't have the encryption key. Even if the disk is foisted out of the machine and installed on a test bed, the data is gibberish.

Products such as SafeBoot Device Encryption provide full disk encryption and are designed specifically for laptops. SafeBoot N.V.'s product requires the user to authenticate with a user ID and password before the operating system loads. Because it loads before the operating system, i


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Information security management for the midmarket
Using key risk indicators to sell your information security program
IT security spending a bright spot in '09, with more growth predicted
Gartner: Vetting security of third-party partners in five steps
Locking down security in the move to electronic medical records
Security and risk management in the midmarket
Identity and access management planning guide for the midmarket
Information systems management for the midmarket
CIOs share advice on doing more with less
Get smart about patching security vulnerabilities
A CIO's advice for implementing single sign-on solutions

Security tools for the midmarket
IT security spending a bright spot in '09, with more growth predicted
Security and risk management in the midmarket
Identity and access management planning guide for the midmarket
A CIO's advice for implementing single sign-on solutions
Options for outsourcing security grow, offer IT budget savings
Network access control: Pointers for getting the knack of NAC
Unified communications: Securing access to OCS
Unified communications security: How safe is it?
Database security: Who should have access?
San Francisco network lockup justifies CIO fears

Security for the midmarket
Locking down security in the move to electronic medical records
A CIO's advice for implementing single sign-on solutions
Options for outsourcing security grow, offer IT budget savings
Network access control: Pointers for getting the knack of NAC
Stopping malware viruses from attacking Web 2.0 technology
Virtual servers no escape from IT security management concerns
Unified communications: Securing access to OCS
Unified communications security: How safe is it?
Risk assessment frameworks easy to employ
Midmarket regulatory compliance management: Don't let your guard down

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


t can't be defeated by Linux boot disks, such as Knoppix, which bypass operating system logons to access machines.

SafeBoot works behind the scenes, continually encrypting the hard drive while the user is working. Similar products are offered by PGP Corp. and GuardianEdge Technologies Inc.

All laptops, like their stationary desktop counterparts, should be outfitted with personal firewalls and antiviral software. They should be up-to-date with the latest security patches. If you use Active Directory for authentication, laptops can be further locked down using Group Policy Objects, again like the desktops that are also connected to the network.

Consider a VPN for secure communication back to the office for those on the road. A Secure Sockets Layer VPN doesn't require any software installed on the laptop but could cost more than an IT professional at an SMB is willing to spend. Products include those from Aventail Corp. and Juniper Networks Inc., and the open source OpenVPN.

If the worst happens, and a laptop is lost or stolen, a theft should be reported to the police and to the incident response team, if you have one, in your IT department. Even without a dedicated information security team, an SMB's IT staff should be informed of what happened. Free tools, like LaptopLock, can be used to register your laptops and can then remotely delete files or encrypt and disable the machine.

With these options, laptop security can be part of an SMB's overall IT security program with existing staff at minimal cost.

Joel Dubin, CISSP, is an independent computer security consultant. He is a Microsoft MVP, specializing in Web and application security, and is the author of The Little Black Book of Computer Security, available from Amazon.com. He has a radio show on computer security on WIIT in Chicago and runs The IT Security Guy blog at http://www.theitsecurityguy.com.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts