meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> Quality Management Articles - Quality Matters Blog

You are here: Home > Blog


Quality Management Articles - Quality Matters Blog

Quality Matters is an independent Management Consultancy based in Maldon, Essex. Here we discuss the latest in Quality and Information Security News.

ISO27001 Laptop Security

More and more details are emerging concerning lax security of data and I am becoming increasingly concerned at the absence of even basic precautions to prevent unauthorised disclosure of data.

There have been laptops stolen, lost or simply forgotten at airports which contain sensitive information. Not long ago a Cabinet Minister had a desktop computer stolen, which had data not normally allowed outside Whitehall. The Minister concerned told the Press that it was safe as it was protected by a password. There was incredulity among those present as passwords are so easily overcome. One wag even enquired if the password was 'PASSWORD'.

Desktops and laptops often store system passwords in cmos which is a volatile store chip within the computer and is kept alive by a small coin type battery on the motherboard. This same chip holds the date and other start-up data. If you remove the battery and leave it for a few minutes, this data is lost and the password is removed. The other type of start-up password is held in an encrypted form on hard disk.

It is relatively easy to boot the computer from a CD or alternative operating system, access the password files and delete them. Rebooting the computer in the normal way shows that the password has been removed.

I am no computer expert, but this easy routine is readily available on the internet and it beggars belief that anyone, let alone, those in Government think that their data is secure when 'protected' in this flimsy way.

In my job I travel widely and I have a laptop which is protected by a password but the data I carry is on a separate removable drive which is encrypted at file level so that even if the drive was stolen and put into another laptop the data could not be accessed.

I use Folder Lock to secure my data. There are many other programmes available but I like this one.

Folder Lock is a fast file-security program that can password-protect, lock, hide and encrypt any number of files, folders, drives, pictures and documents in seconds. Protected files are hidden, undeletable, inaccessible and highly secure. It hides files from anyone other than the authorised user, safeguards them from viruses, trojans, worms and spy ware, and even protects them from networked PCs, cable users and hackers. Files can also be protected on USB Flash Drives, Memory Sticks, CD-RW, floppies and notebooks. Protection works even if files are taken from one PC to another on a removable disk, without the need to install any software. It locks files in Windows, DOS and even Safe Modes.

I know that my sensitive files are protected and that my Clients data is protected.

Labels: , ,


Posted: Monday, 28 July 2008

0 Comments:

Post a Comment


Laptop Data Safety

Basic levels of password protection on laptops are easily overcome by the experienced thief and this is causing considerable concern within the industry.

There are two things you should do:

  1. Physical security - Don't let your laptop out of your sight. Never leave it unattended in a public place. Never leave it in the boot of your car overnight at hotels. Always use a steel cable to attach it to a firm structure when in use outside your normal environment.

  2. Electronic security - Don't have sensitive data on a hard disk in the first place. Use a complex password and if possible second level authentication, such as a token or other device. When the laptop is on but is not being used, use the electronic lock facility to activate the password entry facility. Use a password on any screensaver.


That takes some account of security for the laptop, but with attached devices such as SD cards and USB pen-drives the situation is different:

Anyone stealing the SD Card or Pen-drive can read the data on any computer loaded with similar software. This is clearly a point of vulnerability; the best method to protect this type of device is to encrypt it so that it is useless without the decrypt key.

This protection is not the expensive option it used to be, with open source software freely available. The best of these encrypt and decrypt on the fly and are transparent to the authorised but render the device useless to the thief and in may cases appear to be a blank device.

ISO27001 and Laptop Security

Labels: , , , ,


Posted: Thursday, 21 June 2007

0 Comments:

Post a Comment


Don't Hit Your Laptop

I was with a client recently and using my HP Laptop when it suddenly stopped working, froze completely and refused to do anything at all. I tried to shut it down by Ctrl – Alt Del, but nothing. I was getting very frustrated by this time and uncharacteristically I lost it, I thumped the keyboard. Result: the screen went blank and the laptop never worked again.

This was an expensive tantrum as I had to buy a new laptop, software and then spend what seemed a lifetime setting up the machine.

Worst of all I have lost some important data. I do of course back up but on this occasion this component was missed. A security lapse which shouldn't have happened.

Don't take it out on machines they don't care.

Labels:


Posted: Tuesday, 5 June 2007

0 Comments:

Post a Comment


A A A Yellow font on Black background Black font on White background Black font on Cream background
Quality Matters in your Business Quality Assurance Quality in the workplace Quality in the Office