LAHABRA, Calif. -
The "insider" threat is a security nightmare: employees are responsible-purposefully or accidentally-for about 50% of today's security breaches, according to the 2005 CSI/FBI Computer Crime and Security Survey.
And removable media are helping them do it.
"Changes in technology have made it so easy for employees to internally get our private information," according to Miriam Neal, vice president, information systems at SWFCU.
Neal pointed to ubiquitous thumb drives, some of which can slurp 60 gigabytes of data off of enterprise servers in minutes.
Those same drives, coupled with the vast hard drives in popular MP3 players, can do more than steal data; they can also automatically unload malware onto a company network.
"We have secured ourselves quite well in the past three years from external threats," Neal continued. "But in the past year our focus has been centered on the harm that can come from the inside because of large flash drives."
Worried that employees might be the next victims of social engineering or, worse, join the ranks of those who are deliberately stealing information from their employers, Neal started using the SecureWave Sanctuary Device Control in April.
Neal said Sanctuary helps control or block input/output devices through all ports at the credit union, including USB, Firewire, WiFi and Bluetooth.
The software allows only authorized devices to connect to South Western FCU's network. It also delivers an audit log detailing how and when data is moved in and out of the credit union, explained Dennis Szerszen, senior vice president at Herndon, Va.-based SecureWave.
Sanctuary can provide a greater level of detail with a "bit-for-bit" copy of all data that is read or written, he added.
"With Sanctuary, we can shadow everything that everybody does," said Neal. "If employees are allowed to use a flash drive or compact disc, Sanctuary shadows it. If employees upload a spyware engine that would transmit private information to a flash drive or from a flash drive, I have a shadow of it."
The Sanctuary dashboard allows Neal to enforce the credit union's written policies on data and removable media: employees are not permitted to remove private information or software licenses, and they can't use USB ports or CD-ROMs without permission, said Neal.
Neal can automatically identify each device and assign permissions down to a specific user or application. She can also limit the amount of access time for each device or require particular levels of encryption.
"Let's say the CEO needs to use a CD-ROM," Neal said. "With Sanctuary, we can open up the drive for her for a period of time. Even then, we shadow her device so that we know what's going on."
The $170-million CU has yet to lose data to employees, Neal said.
FOR MORE DETAILS
Visit the sources in this story at:
* South Western FCU at www.swfcu.org
* SecureWave at www.securewave.com











