Find White Papers
Home
About Us
List Your Papers
    
> Pointsec > Risk-Free Travel: A Look At Swiss Re

Risk-Free Travel: A Look At Swiss Re

Case Study Published By: Pointsec

Critical data is best protected against misuse on business trips complete encryption of notebook hard disks. If 4,500 notebooks are involved, as is the case for the Zurich firm Swiss Re, precise selection criteria and exact planning for the international rollout are important.



Tags : 
data protection, laptop, lost laptop, lost notebook, encryption, data encryption, laptop encryption, vulnerability

Pointsec
Published:  Aug 21, 2009
Type:  Case Study
Length:  3 pages

Pointsec - the de facto security standard for mobile devices and PCs
AUTHENTICATION AND ENCRYPTION
BRy Jürgiesn Waksem--Guftenrsoehn* e Travel
Critical data is best protected against misuse on business trips by complete en-cryption of notebook hard disks. If 4,500 notebooks are involved, as is the case for the Zurich ?rm Swiss Re, precise selection criteria and exact planning for the international rollout are important. It's all in the name - for example "Enigma". An encryption machine bearing this name was de-signed back in the 1920s. The Enigma machine was used ?rst in the civil commercial ?eld and later by the military. Enigma is also the name chosen by Swiss Re for its IT project involving the encryption of 4,500 notebooks. The laptops are used by employees who travel a lot, commute between different locations or occasionally work in a home of?ce. The reason behind the project is that the password protection in Windows XP was not adequate for those in charge at the reinsur-ance company. Notebooks protected in this way are open to any form of misuse within minutes with easily available hacking tools.
However, complete encryption of notebook hard disks, including the operating system and data, prevents unauthorized persons from reading the data. To ?nd the right solution, the project team was asked to de?ne selection criteria and to assess the products offered on the market on that basis.
SELECTION CRITERIA SEPARATE THE WHEAT FROM THE CHAFF"The essential requirement for an encryption solution for mobile termi-nals is that it must be compatible with the existing server infrastructure, the application components on the laptops and the software distribution mechanism," stresses Fredi Schmid, the competent Project Manager at Swiss Re in Zurich. "This also means that the software can be installed automatically during operation (i.e. without support employees on site) on the devices in use. The solution currently used, Pointsec for PC, meets these requirements." Installation should be as easy as possible for users. If complete encryption of notebook hard disks runs in the background, according to Schmid, the user can largely perform his daily work undisturbed.
The encryption of the entire notebook hard disk is binding on all notebook users. This means complete sector-by-sector encryption of the entire hard disk. This includes not only the storage areas in use but also areas with temporary or deleted ?les and the space not currently in use. For this reason, complete encryption is necessary. The Swiss Re headquarters were built The necessity of compliance with the encryption measures also means in 1913 and are located very close to that even employees with administration rights on a notebook cannot Lake Zurich. (Source: Swiss Re)disable or delete encryption software that has been installed. Measures are also necessary for cases in which users enter the wrong password repeatedly or have forgotten the combination of characters they chose. If a company has consciously decided against a central repository with all passwords, a challenge-response procedure between the user and the administra-tor helps in such cases. The user must ?rst identify himself to the helpdesk. The user then generates a chain of characters (challenge). The administrator, who administers the user accounts but not the passwords, responds with the suitable response. The central administration software determines the Pointsec - the de facto security standard for mobile devices and PCs
response on the basis of the challenge. It is important that each response applies for only one access attempt. There-fore, the challenge-response procedure is superior to the transmission of encrypted passwords.
After a detailed evaluation of several quotations, Swiss Re decided on the Pointsec solution. "First of all, we were impressed by the technology. Another feature in its favor is the user authentication in addition to the actual encryp-tion. This protection function works immediately after the devices are switched on, i.e. even before they actually boot up," stresses Schmid. "Secondly, the international experi- Critical data stored on notebook hard disks ence of Pointsec from the rollout of extensive installations is best protected against misuse by complete also played an important role in the decision." encryption of the hard disks.
256-BIT DATA ENCRYPTIONThe encryption algorithm used in the Pointsec... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search