Home > Ask the Information Security Experts > Questions & Answers > How can a corporation assess the costs of whole-disk encryption?
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

How can a corporation assess the costs of whole-disk encryption?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 23 September 2007
As part of the risk assessment process, how can an enterprise develop a realistic assessment of the cost of whole-disk encryption?

>
EXPERT RESPONSE
Addressing this issue is like sizing and estimating rollout costs of anything else. There are both direct and indirect costs. You take a stab at estimating, build a few ranges because the estimates are going to be wrong, and take a cut at the numbers.

The direct costs are pretty straightforward. You need to buy software and you need to deploy it. Consider the cost of the software and be sure to include ongoing maintenance, since that won't be free in future years. Then there are direct deployment costs. Will an IT staff member be needed to install the software, or is there a software distribution engine that will take care of it?

Also factor in some training costs, because users need to understand what's been installed on their machines and how to use it. Relative to whole-disk encryption, also make sure users understand what to do if they lose their password. You don't want to get a call at 3:00 a.m. as your CEO is in a foreign land and has locked himself out of the machine.

Where it gets a bit squishy is in estimating the indirect costs like additional help desk resources because users forget their passwords and cannot access their machines. Or someone hits the wrong switch and blows away all his or her data. These things and more are going to happen, so make some estimates and then monitor the data closely as the products are rolled out.

Keep the cost model close at hand because it will be changing as you go through the pilot and early implementations.

For more information:

  • In this tip, contributor Lisa Phifer discusses encryption strategies for preventing laptop data leaks.
  • In this expert response, learn which Unix programs can encrypt database files.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Risk Assessment Analysis
    Reports show security awareness and training are still lagging
    Data threats: Insiders vs. outsiders
    Managed services company finds way to automate support
    RSA gets control of security, risk with Agiliance compliance solution
    Database patch denial: How 'critical' are Oracle's CPUs?
    Is personal Internet usage acceptable for employees in the workplace?
    Windows registry forensics guide: Investigating hacker activities
    Security strategy research seeks to plug weaknesses
    Bank security chief explains how to avoid internal threats
    Data loss prevention doesn't come in a pill

    Enterprise Data Storage
    Local council finds better way to track lost laptops
    Will the rise of SharePoint services lead to increased data loss?
    Scottish NHS trust ensures no repeat of USB data loss
    Finance sector poor at achieving outsourcing success
    Mobile technology may limit harm of laptop data loss
    HSBC loses customer data in the post
    How to lock down USB devices
    Another day, another embarrassing data loss
    How to achieve laptop data security
    Chemical giant says data leakage tools not up to snuff

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Serious Organized Crime Agency  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts