Home > Information Security News > Scottish NHS trust ensures no repeat of USB data loss
Information Security News:
EMAIL THIS

Scottish NHS trust ensures no repeat of USB data loss

By Ron Condon, UK Bureau Chief
06 Nov 2008 | SearchSecurity.co.uk

Security UK News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

A Scottish health trust has moved quickly to prevent further security breaches following the loss of a USB stick in July.

NHS Lothian has implemented technology to ensure that from now on only approved and encrypted USB pen drives can be used to carry personal data.

Martin Egan, director of e-Health at NHS Lothian, said he has introduced a new system whereby up to 4000 users will be provided with USB devices for work use only, and which will be encrypted and password protected. Visitors will still be able to use their own USB drives, for instance to show PowerPoint presentations, but they will be prevented from writing data on to their drives.

The trust is using Sanctuary Device Control from Arizona-based Lumension Security Inc. to encrypt all approved devices, including USB drives, CDs and DVDs. It will also provide an audit trail of device usage and data transfer, and prevent the introduction of malware via removable media.

In addition, the trust will use the Disk Protect and Connect Protect products from UK encryption software firm Becrypt Ltd. to ensure full-disk encryption on all laptops in the trust, as well as control any transfer of confidential data from laptops to USB sticks.

Enrolment of users began in late October. "At the configuration of the USB device the user has to be present, and enter a password of suitable strength, and that becomes the encryption key for that particular USB stick," said Egan. The stick will act as a security token as well as an encrypted storage device for the user.

Egan said the MAC address of each USB stick was recorded and tied to the individual user. If the stick is lost, the account can be disabled, and if users forget their password, they have to present themselves in person once again to configure the device and register a new password.

Passwords will not be changed or updated, said Egan. "We decided not to force password changes. It is a difficult call, but if you make people remember too many passwords, you can end up making the system less secure.

"Other USB devices can connect to the network but only on a read-only basis. We automatically virus-check anything that is plugged into the machine."

The new system follows an embarrassing breach that occurred last July when an employee lost a USB stick that contained letters with personal information relating to 137 patients. The information had been stored by the member in breach of regulations that prohibit the storing of NHS information on personal portable computing devices.

While Egan believes the new system will prevent a repeat of the mistake, he is backing it up with a new security awareness campaign. "You've got to protect people from themselves sometimes. We cover off IT security and governance at induction, but a lot of people have been around a long time and are maybe a little rusty on that," he said. "We are now backing this up with communications that will be sent out with everyone's payslip, to remind them of their responsibilities when handling personal information. The message to them is that data security is business."

Tags: Data Protection Solutions and StrategyEnterprise Data StorageVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Data Protection Solutions and Strategy
Enterprise data management: Prevent data loss and insider threats
NSA, cryptoexperts jab at RSA Conference 2010 Cryptographers' Panel
Make PCI DSS compliance easier by reducing scope, outsourcing data
Data Protection Act fines likely limited, audit powers may expand
Websense integrated security system aims to simplify security management
Full disk encryption: Safer and easier than file and folder encryption
No major PCI DSS revision expected in 2010
Data breach costs continue to rise in 2009, Ponemon study finds
Chinese hacker attacks target Google Gmail accounts, top tech firms
Annual security reports offer some hope

Enterprise Data Storage
Safend expands data leakage prevention product to plug more gaps
TrueCrypt: How to get started with open source disk encryption
Report: Firms avoid encrypting backup tapes, databases
Encryption tips: How to secure a laptop
The real reason behind backup recovery disk failures
Infosec pros wake up to Excel spreadsheet security risks
How to enforce an enterprise data leak prevention policy
3ami allows employers to track use of USB storage devices
How to create a data classification policy
EMC adds configuration management with Configuresoft acquisition

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
UK Identity Cards Act  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



IT Solutions for the UK: Data Security, Network Security, Application Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts