layton logo    
     
  Endpoint Security  
 
 
  What is Endpoint Security?

Endpoint Security means different things to different organizations but is essentially the sum total of the measures taken to implement security concerning endpoints. Endpoint Security logically extends to the management and administration of these security measures, as well as to the risk, reporting, and knowledge management of the state and results of these measures.

Today’s businesses are under more stringent regulatory obligations than ever in terms of managing their data and so must be increasingly vigilant, juggling the need for protection against leakage to unauthorized parties whilst at the same time making it available, where appropriate to their workforce. 

With mushrooming volumes of data in circulation the risk of security breaches, leaks or loss has never been higher and whilst IT security policies applied viruses, hackers and malicious information leaks have long been considered mandatory, many businesses are still ignoring the threats emerging in the key areas of privacy, employee misuse, intellectual property and corporate compliance.

Today’s reality is that portable devices like iPod’s, Smartphones, PDA’s and USB thumb drives are now commonplace throughout the workplace. Inexpensive and easy to conceal, they have considerable storage capacity and while these devices are great for productivity, convenience and entertainment, they can pose serious risks to your business including:


Threats Explored

Data Theft
Employee Misuse
Malware Injection ( HIPAA , GLBA , Sarbanes-Oxley )

DeviceShield enables you, as part of your broader IT security plan, to prevent the use of unauthorized storage devices to eliminate these threats.


Data Theft:

In 2004, reported losses due to unauthorized access and theft of proprietary data totaled $60 million which were the result of a single theft. Fast forward to the present and in March 2008 alone there were ELEVEN high profile losses. DeviceShield prevents the use of unauthorized removable devices, tracks any storage devices that are used, and protects valuable personal and corporate data from theft. top


Employee Misuse:

Well intentioned or otherwise, every time an employee copies any of your company’s data to a removable device such as a USB thumb drive, your business is at risk. Small and easily lost, they leave your business data vulnerable to whoever happens to find the device, as evidenced in the news every week.  By deploying DeviceShield, you can prevent the use of unauthorized removable devices throughout your company and ensure that sensitive data and office resources are protected and used appropriately. top


Malware Injection:

Business networks are susceptible to malware attack from many directions, including all types of removable storage devices, an example being an employee that uses a USB thumb drive to transfer files between a home and office computer. If the home computer is not protected with up-to-date anti-virus software, the transferred files could infect your network.  DeviceShield allows you to prevent removable device access and so helps secure your network from malware. top


Regulatory Compliance:

As part of a best practice approach to corporate governance and in order to comply with a variety of regulatory requirements, most business’s must be able to prove that they have appropriate IT security controls in place. DeviceShield is a robust, set and forget Endpoint security solution that offers exceptional value for money, providing today’s busy IT department with full control over removable media, thus helping to ensure that ever more demanding business critical corporate compliance issues are met with confidence. top


Health Insurance Portability and Accountability Act (HIPAA):

HIPAA requires that an organization must restrict access to Protected Health Information (PHI) to only those employees who need such information to do their jobs.  Access to systems containing PHI must be tightly controlled and monitored to ensure that the HIPAA requirements are met.  DeviceShield helps organizations comply with HIPAA by ensuring that removable devices cannot be used to improperly copy or transfer this information.  top


Gramm-Leach-Bliley Act (GLBA):

GLBA (also known as the Financial Services Modernization Act) regulates the handling of personal financial information. The GLBA requires that companies operating in the financial sector maintain a comprehensive data security plan regarding the protection of such data. DeviceShield plays an important role in this plan by eliminating the risk posed by removable devices. top


Sarbanes-Oxley Act (SOX):

SOX makes corporate executives explicitly responsible for establishing, evaluating and monitoring the effectiveness of internal controls over financial reporting.  These data security controls are required to be fully auditable and DeviceShield provides companies with an effective solution for enforcing these guidelines along with an audit trail to prove compliance. top


The Cost of Doing Nothing

The actual cost of doing nothing in terms of customer loyalty, financial, legal and even brand reputation is difficult to quantify but according to a recent survey carried out by Michigan based Ponemon Institute estimates that data breaches cost US companies an average of $182 per compromised record in 2006, a 31% increase over 2005. The TJX Companies, Inc. security breach, which took place from July 2005 to December 2006 and which many experts cite as the biggest case to date, is estimated to have cost TJX more than $5m, but the long-term impact on its brand, financial performance and customer loyalty is yet to be fully realized. top


Endpoint Security Myths

Do you Recognize any of these?

“IT can and should restrict the types of users, endpoint platforms, and access technologies that may connect to the enterprise network.”
“The traditional network security perimeter provides adequate protection against endpoint security threats.”
“End-users can be trusted to follow best practices to maintain a secure endpoint environment.”
“We can wait until next year to worry about regulatory compliance issues.”
“One endpoint security policy fits all.”
“Microsoft and Cisco will sort out these issues for me.
 
 
 
© Copyright Layton Technology 2008. | Standard Software License Agreement
site map icon Site Map ClickReport