Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 49 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Compliance, Regulations & Standardsarrow Recommended Security/Encryption suite
EH-Net
May 24, 2013, 08:05:15 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Recommended Security/Encryption suite  (Read 9209 times)
0 Members and 1 Guest are viewing this topic.
tux633k
Newbie
*
Offline Offline

Posts: 9


View Profile
« on: June 30, 2010, 07:27:41 PM »

Hi I wasn't sure if I should post this topic here, but in any case I was wondering if anyone has any recommendations on an Encryption software suite to do it all - encryption/decryption, pwd mgmt, usb encryption etc.  I just don't want to break the bank so to speak.  I'd like for it to be affordable but I might be asking for too much already.  We're a small shop of about 100 employees but I may not need to encrypt everyone's system just those that deal with sensitive/confidential data.  From what I read I like the GuardianEdge software but I don't know how much this costs.

Thank you.
Logged

CEH, MCP, CSCS, CHP
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #1 on: July 01, 2010, 07:25:54 AM »

The problems you WILL run into will be the management of the suite and user-end training. An issues with simply allowing users to run their own "privacy suite" is when their employment comes to an end. What will you do if you don't have the ability to decrypt what an employee encrypted.

Imagine for a minute having a top scientist at your company. He discovers the cure for Foobalia a terminal disease. He's been taught to encrypt everything he does and does so. He passes away... He leaves for another job... He is arrested... *Something* happens where you need that data. What are you going to do. How much time and money will it cost you to attempt to recover that data.

Let's look at the alternative. 100 Employees. You will need to train them all, mandate they all use it, configure it, maintain it. So you think... "rescue disk!"

RD = Rescue Disks
M = Minutes

100(RD) * 20(M)  = 2000 / 60 = 33 hours to configure

There is a hidden slash un-thought-about cost factor here. You could (if properly) deploy a script to autodownload, install, back-up the program. However, there is still management and user-end training.

On the low end of the pricing spectrum there is Steganos which doesn't allow for *true* enterprise scalable configuration.
http://www.steganos.com/us/products/data-security/privacy-suite/overview/

Then there is something like Voltage (http://www.voltage.com/products/index.htm) where all is centralized including being able to send out emails where the receiver (even if they don't have say PGP) could decrypt. Key management is made simple so you don't run the risk of say rogue employees changing keys/pasphrases, etc.

Voltage at the end of say a 3-5 year lifespan will eventually come out cheaper via terms of configuration, deployment, usability not to forget that if someone leaves, you won't shoot yourself in the foot wondering whether or not your data is gone (encrypted beyond the point of no return)
Logged

yatz
Full Member
***
Offline Offline

Posts: 222


View Profile WWW
« Reply #2 on: July 01, 2010, 08:15:51 AM »

I think a combination of Rights Management (RMS) and Bitlocker.  Again, it depends on your environment, but if you are running Windows then this kinda stuff comes with Vista/7 and Windows Server 2008.
Logged

"Live as though you would die tomorrow, learn as though you would live forever."

CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
former33t
Full Member
***
Offline Offline

Posts: 226


View Profile
« Reply #3 on: July 06, 2010, 06:38:39 PM »

I'm with Sil on using Voltage.  They simplify key management and data recovery, which will be your biggest concerns in any company of more than say five employees...  A truly stable PKI implementation for a company of your size will cost a LOT to deploy in terms of man hours. I have to assume that you have a full time job before trying to develop and deploy a PKI so something that is more or less plug and play is probably your best option (as it doesn't sound like you have enough people to justify a consultant to deploy the infrastructure for you.

Whatever you do, don't cut corners.  A bad PKI design likely makes your information MORE vulnerable.  People start to consider all critical information being encrypted as a mitigating factor for other vulnerabilities (which is really isn't).  Then people leave holes open that they wouldn't otherwise.  Bad situation all around.

Good luck.
Logged

Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.07 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.