<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecurityNowBlog&#187; SecurityNowBlog-Network Security</title>
	<atom:link href="http://www.blueridgenetworks.com/securitynowblog/tag/usb-thumbdrive/feed" rel="self" type="application/rss+xml" />
	<link>http://www.blueridgenetworks.com/securitynowblog</link>
	<description>Secure Communications</description>
	<lastBuildDate>Wed, 28 Sep 2011 18:27:53 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Business Partner Data Leak Prevention</title>
		<link>http://www.blueridgenetworks.com/securitynowblog/business-partner-data-leak-prevention</link>
		<comments>http://www.blueridgenetworks.com/securitynowblog/business-partner-data-leak-prevention#comments</comments>
		<pubDate>Thu, 21 Aug 2008 18:48:39 +0000</pubDate>
		<dc:creator>Eirik Iverson, Product Management</dc:creator>
				<category><![CDATA[Endpoint Security]]></category>
		<category><![CDATA[anti- anti-spyware]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[application control]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[browser security]]></category>
		<category><![CDATA[data leak prevention]]></category>
		<category><![CDATA[disk encryption]]></category>
		<category><![CDATA[endpoint]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[NAC]]></category>
		<category><![CDATA[nap]]></category>
		<category><![CDATA[network access control]]></category>
		<category><![CDATA[network access protection]]></category>
		<category><![CDATA[Network Admission Control]]></category>
		<category><![CDATA[p2p]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[usb thumbdrive]]></category>
		<category><![CDATA[web browser]]></category>

		<guid isPermaLink="false">http://www.securitynowblog.com/?p=15</guid>
		<description><![CDATA[If your business partners are accessing your sensitive data on your mission critical servers, you may find yourself living in excessively interesting times.
A signed agreement among business partners helps, but guarantees nothing. Incidentally, it can also discourage disclosure. Persuading them to implement better information security practices (i.e., spend more) can be fruitless.
Despite the difficulties, we [...]]]></description>
			<content:encoded><![CDATA[<p>If your business partners are accessing your sensitive data on your mission critical servers, you may find yourself living in excessively interesting times.<span id="more-15"></span></p>
<p>A signed agreement among business partners helps, but guarantees nothing. Incidentally, it can also discourage disclosure. Persuading them to implement better information security practices (i.e., spend more) can be fruitless.</p>
<p>Despite the difficulties, we often need an agreement signed to help facilitate avoiding the following risks posed by our business partner endpoints:</p>
<ul>
<li>Infect our mission critical servers (Risk 1)</li>
<li>Leak data via malware (Risk 2)</li>
<li>Leak data via removable media (Risk 3)</li>
<li>Leak data via high-risk endpoint hard drives (Risk 4)</li>
</ul>
<p><strong>Limit server access to partner endpoints of acceptable risk.</strong><br />
Limit access to machines not just people. Limiting access based on both identity and health requires network access control (NAC) technology, such as Microsoft Network Access Protection (NAP).</p>
<ul>
<li>Try to limit access to machines that process as little data, documents, or media from the outside world as practical (Risk 2). This also means denying access to endpoints running p2p and other software.</li>
<li>Ensure that anti-virus and anti-spyware software are running, up-to-date, and frequently conduct full scans (Risk 2)</li>
<li>Try to require other anti-malware tools because signature-based anti-malware products are becoming more ineffective every week (Risk 2).</li>
<li>Deny access to endpoints with promiscuous removable media settings (Risk 3)</li>
</ul>
<p><strong>Data stored on partner endpoints must be encrypted.<br />
</strong>Fixed and mobile PCs can be physically compromised. Limit server access to endpoints with full disk encryption (Risk 4). Second, also limit access to machines that require two factor authentications to utilize the endpoint (Risk 4). If your partner&#8217;s disk encryption solution can ensure that write operations to removable media are encrypted, then you might ease up on removable media settings requirements (Risk 3).</p>
<p><strong>Consider limiting partner server access to thin client machines.</strong><br />
One can be very confident that no malware is operating within a freshly <strong>rebooted</strong> thin client machine (Risk 1). This can also be the most effective, albeit Draconian, risk mitigation to data leaks (Risk 2, 3, and 4). BTW, you could also have them access mirrors of your mission critical servers instead (Risk 1).</p>
<img src="http://www.blueridgenetworks.com/securitynowblog/?ak_action=api_record_view&id=15&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.blueridgenetworks.com/securitynowblog/business-partner-data-leak-prevention/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

