Data erasure news / issue 2

4
Does your organization manage sensitive data properly? Data Erasure Throughout the Asset Lifecycle Part of an effective data security policy involves implementing data erasure solutions throughout an IT asset’s life, not just when it reaches the end-of-lifecycle phase. “This means whenever temporary, confidential, or top secret data is no longer needed at your organization, data erasure solutions should be utilized to safely remove data and generate a legally compliant audit trail to facilitate the safe reuse of an IT storage device,” according to Sami Tuupanen, Director of Products and Services at Blancco. START OF LIFECYCLE When an IT asset enters an organization, asset management software can be used to track information on the device. However, this offers no way to maintain a record about the management of data on the device and how it was securely handled. Blancco Management Console can be used to maintain information about an asset and any applied erasure processes. It is designed to help manage IT asset disposal processes, including erasure software distribution, hardware asset management, and erasure reporting. The Blancco Management Console API can be used to integrate the Management Console with asset management software, enabling full automation to centralize IT asset management and track all devices, making it the perfect tool to help an organization manage the lifecycle and secure erasure of all assets. Comprehensive Reporting is performed by all of Blancco´s erasure products to issue crucial evidence that each erasure was successfully completed. These tamper-proof and verifiable reports are an essential part of compliance, regulatory and legal requirements. Reports should be generated at all stages of the data destruction lifecycle to ensure that a legally compliant audit can be performed later on. The integration of Blancco Management Console with asset management software supports an organization’s ability to effectively manage, secure and audit the lifecycle of assets and data. DURING THE LIFECYCLE Robust asset management involves the secure deletion of protected information throughout the lifecycle. For example, an enormous amount of confidential data is stored on virtualized storage (such as the cloud), which must be erased when the information is no longer needed. Individual files such as internal design documentation and credit card details on selected computers must be targeted for erasure when they are no longer required. To avoid unnecessary risk, Blancco’s suite of software solutions can meet all of an organization’s data erasure needs. Blancco LUN allows data storage administrators to securely erase segments of data in active storage environments. This includes logical units in virtualized environments or any type of drive supported by UNIX or Windows operating systems. The erasure processes can be scheduled or run on demand to suit an organization’s requirements. Blancco File can securely destroy individual files and folders from specified locations with given rules and parameters. Tasks can be automated to ensure that data erasure actions are performed within predefined rules resulting in targeted and consistent removal of data. Blancco Flash erases data from solid-state removable storage media such as USB thumb drives, Secure Digital memory cards, CompactFlash cards and others. It supports plug and play to automate the process, minimizing usage time. END OF LIFECYCLE/OWNERSHIP CHANGE At the end of the lifecycle phase it is vital to ensure the complete erasure of the asset. This is why it is critical to use robust software to wipe all data and accurately report the process when an asset is reassigned to another person at a company, or is being disposed of. Failure to effectively erase a device can result in costly data leaks and negative publicity for an organization. In some situations, i.e. when the device is defective, degaussing can be used. Blancco 4 & Blancco 5 can securely erase data from PCs, laptops, servers and storage environments. These fully automated and centrally managed solutions provide cutting edge efficiency and productivity to meet the complex needs of organizations managing multiple data storage devices. Blancco Mobile securely erases the internal and external memory of another key asset type: smartphones and tablets. Restoring factory settings does not ensure that data is permanently destroyed, because the data can still be recovered afterwards. Blancco Mobile also ensures that the device is reusable with the standard OS (operating system), while providing peace of mind that all critical corporate data is removed. Blancco Degausser can be used when hard disks or other magnetic media become defective and inaccessible to software. A degaussing machine destroys data on a hard drive through the use of a strong electromagnetic field. IN THIS ISSUE: CEO News ® How an Organization Can Prevent Data Leaks ® Global Support Localized ® NHS Case Study from the UK ® Blancco Expands Globally ® The Benefits of Reporting ® Why Erase Data? Have you thought about what could ultimately happen if your organization’s assets were to end up in the wrong hands? ISSUE 2, SEPTEMBER 2013 | This magazine is published by Blancco Oy Ltd. Copyrights 2013 Blancco Oy. All rights reserved.

description

 

Transcript of Data erasure news / issue 2

Page 1: Data erasure news / issue 2

Does your organization manage sensitive data properly?

Data Erasure Throughout the Asset LifecyclePart of an effective data security policy

involves implementing data erasure

solutions throughout an IT asset’s life, not

just when it reaches the end-of-lifecycle

phase. “This means whenever temporary,

confidential, or top secret data is no

longer needed at your organization, data

erasure solutions should be utilized to

safely remove data and generate a legally

compliant audit trail to facilitate the safe

reuse of an IT storage device,” according

to Sami Tuupanen, Director of Products

and Services at Blancco.

STarT of LIfecycLe

When an IT asset enters an organization,

asset management software can be used to

track information on the device. However,

this offers no way to maintain a record

about the management of data on the

device and how it was securely handled.

Blancco Management console can be

used to maintain information about an

asset and any applied erasure processes.

It is designed to help manage IT asset

disposal processes, including erasure

software distribution, hardware asset

management, and erasure reporting. The

Blancco Management Console API can

be used to integrate the Management

Console with asset management

software, enabling full automation to

centralize IT asset management and track

all devices, making it the perfect tool to

help an organization manage the lifecycle

and secure erasure of all assets.

comprehensive reporting is performed

by all of Blancco´s erasure products to

issue crucial evidence that each erasure

was successfully completed. These

tamper-proof and verifiable reports are an

essential part of compliance, regulatory

and legal requirements. Reports should

be generated at all stages of the data

destruction lifecycle to ensure that a legally

compliant audit can be performed later on.

The integration of Blancco Management

Console with asset management software

supports an organization’s ability to

effectively manage, secure and audit the

lifecycle of assets and data.

DurIng The LIfecycLe

Robust asset management involves the

secure deletion of protected information

throughout the lifecycle. For example, an

enormous amount of confidential data is

stored on virtualized storage (such as the

cloud), which must be erased when the

information is no longer needed. Individual

files such as internal design documentation

and credit card details on selected computers

must be targeted for erasure when they are

no longer required. To avoid unnecessary risk,

Blancco’s suite of software solutions can meet

all of an organization’s data erasure needs.

Blancco Lun allows data storage

administrators to securely erase segments

of data in active storage environments.

This includes logical units in virtualized

environments or any type of drive supported

by UNIX or Windows operating systems. The

erasure processes can be scheduled or run on

demand to suit an organization’s requirements.

Blancco file can securely destroy individual

files and folders from specified locations with

given rules and parameters. Tasks can be

automated to ensure that data erasure actions

are performed within predefined rules resulting

in targeted and consistent removal of data.

Blancco flash erases data from solid-state

removable storage media such as USB

thumb drives, Secure Digital memory cards,

CompactFlash cards and others. It supports

plug and play to automate the process,

minimizing usage time.

enD of LIfecycLe/ownerShIP change

At the end of the lifecycle phase it is vital to

ensure the complete erasure of the asset. This

is why it is critical to use robust software to

wipe all data and accurately report the process

when an asset is reassigned to another person

at a company, or is being disposed of. Failure

to effectively erase a device can result in

costly data leaks and negative publicity for an

organization. In some situations, i.e. when the

device is defective, degaussing can be used.

Blancco 4 & Blancco 5 can securely erase

data from PCs, laptops, servers and storage

environments. These fully automated and

centrally managed solutions provide cutting

edge efficiency and productivity to meet the

complex needs of organizations managing

multiple data storage devices.

Blancco Mobile securely erases the

internal and external memory of another

key asset type: smartphones and tablets.

Restoring factory settings does not ensure

that data is permanently destroyed,

because the data can still be recovered

afterwards. Blancco Mobile also ensures

that the device is reusable with the

standard OS (operating system), while

providing peace of mind that all critical

corporate data is removed.

Blancco Degausser can be used when hard

disks or other magnetic media become

defective and inaccessible to software. A

degaussing machine destroys data on a

hard drive through the use of a strong

electromagnetic field. �

In thIs Issue: CEO News ® How an Organization Can Prevent Data Leaks ® Global Support Localized ® NHS Case Study from the UK ® Blancco Expands Globally ® The Benefits of Reporting ® Why Erase Data?

Have you thought about what

could ultimately happen if your

organization’s assets were to end up

in the wrong hands?

ISSue 2, SePTeMBer 2013 | This magazine is published by Blancco Oy Ltd. Copyrights 2013 Blancco Oy. All rights reserved.

Page 2: Data erasure news / issue 2

Having the privilege of attending the

Ernst & Young World Enterpreneur of

the Year Competition was invaluable

to me. I had the honor of representing

Finland as one of 49 entrepreneurs from

over 50 different countries vying for the

world title in Monte Carlo last June. I

learned that passion, energy, and focus

are essential to succeed in the world

of business as an entrepreneur, and no

matter what your roots, the drive to

succeed is necessary to garner success.

CeO newsCEO and Co-Founder Kim Väisänen

My days in Monte Carlo were chock full of

interviews, attending event presentations

and meeting new people such as world

renowned individuals including Kofi Annan,

former United Nations Secretary General,

Dambisa Moyo, international economist

and author, John Cleese, actor, author

and comedian, and even Prince Albert

of Monaco. Returning home to Finland

inspired me to further think of how we at

Blancco can further develop our product

and customer relationships.

We at Blancco strive to be a truly innovative

company and brand. We want to do our

utmost to serve you, our valuable customer,

with the most leading-edge data erasure

solutions on the market. Therefore, we invest

time and resources in product management

and research.

We have a global sales support network

ready to assist you at our 17 different

offices in 15 different countries. We also

Finland

We at Blancco strive to be a truly

innovative company and brand. We

want to do our utmost to serve you,

our valuable customer, with the most

leading-edge data erasure solutions.

froM PrevIouS Page�

concLuSIon

Administering solutions to manage

the secure erasure of data on a device

is an important part of corporate asset

management. Blancco Management

Console allows your organization to fully

automate the process, together with a full

array of Blancco products to suit every

erasure need. These can be seamlessly

integrated through the Management

Console with your organization’s own asset

database and provide comprehensive

data reports and statistics. Reporting

creates a comprehensive audit trail and

provides other important details to create

a complete picture of the asset’s lifecycle.

Have you thought about what could

ultimately happen if your organization’s

assets were to end up in the wrong

hands? “Proper data erasure management

can create peace of mind and help your

organization avoid fines and the damage

that a loss of reputation or intellectual

property can bring,” Tuupanen asserts. ®

How An Organization Can Prevent Data LeaksTargeted data erasure is ideal for removing

confidential data such as credit card

details, confidential customer information

and internal office documents to prevent

data leaks. Blancco file securely erases

selected data to ensure full compliance

with new legislation and regulations

demanding secure removal of customer

data such as the PcI DSS (Payment card

Industry Data Security Standard) and the

upcoming eu Protection Directive. This

advanced file shredding solution makes

day-to-day shredding easy and supports

all leading erasure standards.

Blancco File is DIPCOG* approved, and one

of Blancco’s most flexible software solutions

for corporate and enterprise companies. The

software can be installed in both Windows

and Unix environments and is used for

securely erasing files, folders, free disk space,

temporary files and even virtual machines.

This also makes it a useful tool in data centers

as it compliments Blancco LUN for a combined

erasure of both the virtual machines and the

virtual drives that they manage.

Scripting and automation

Scripting and automation are some of the

most sought after features of this product.

Erasures can be set to perform automatically

at a certain time and/or day. Rules can also

be set to target specific file extensions. As

an example, if a .docx file is converted into

.pdf and must then be erased, Blancco File

can be scripted to automatically target

the .docx for erasure after the conversion

is complete. Erasures are also possible in

virtual environments such as ESX and ESXi

where the datastore of a virtual machine

needs to be securely removed instead of just

the inventory.

examples of use

An administrator has the ability to install

Blancco File on all client computers by

pushing an MSI installation package

through the network so every end-user will

be able to target their daily files and folders

for secure erasure. The administrator also

has the ability to use Group Policy Objects

to limit and/or configure the ability of end-

users. One example would be setting a rule

for all erasures using the Department of

Defense three-time overwriting method.

Many other scenarios are possible for using

Blancco File. Network erasures are possible

for users who have access to network shared

folders and files. Erasures through NFS

(Network File System) and CIFS (Common

Internet File System) are a popular solution

as well. Integration with Microsoft’s FCI

(File Classification Infrastructure) is possible

in case a company has the need to search

through entire folder structures to find

certain documents. This means all files can

be targeted within the folder structure for

automatic erasure is possible rather than

manually digging for specific files which

saves time, ensures 100 percent success, and

removes the possibility of human error.

audit trail

After every erasure, a report will be

generated as proof. These reports contain all

of the necessary information such as the file

name and time of the erasure. The reports

can be stored locally, sent via email and

sent to the Blancco Management Console

for synchronization with a database for a

complete audit trail. ®

exeCutIOn methOds

Blancco File is driven in three different ways:

1. User-driven execution

When the user of the computer

gives the “Erase” command.

2. Event-driven execution

When an event dictates that

an erasure will be performed.

For example, when a .docx is

converted into .pdf, the .docx is

then automatically erased.

3. Policy-driven execution

When a company must comply

with local or global regulations

by securely erasing their data.

For example, all data from former

customers must be erased after

six months.

* The Defence INFOSEC Product Co-operation Group of the UK

Complete our 30-second

Customer Survey and be

eligible for Monthly Prizes!

have localized technical support to serve

our customers in eight different languages

which is coordinated from local offices who

liaise with our headquarters office to give

you service at each of our global locales.

We welcome your feedback which can help

with further development of our brand to

further improve your organization´s erasure

process efficiency and secure crucial data. ®

View short video clip from Monte Carlo event:

http://bcove.me/zc2vrr7c

http://bit.ly/15ieJwf

Data ErasurE nEws2

Folder Structure

Credit Card Information Con�dential Document Strategy Plan

Page 3: Data erasure news / issue 2

Q&a with Blancco’s Technical Support Manager

Blancco’s Technical Support Manager, harri hirvonen, facilitates

the flow of information for the Technical Support Team and

designs support processes globally. He and his staff of 14

Technical Support Engineers and Specialists, located around the

globe, help customers to utilize Blancco’s data erasure product

solutions. The main technical support hub, located at the

company’s headquarters in Joensuu, Finland, interfaces with all of

Blancco’s offices around the world.

Global Support Localized

Case study: The North & East London CSU Erases Patient Data with Blancco

Q: what is the main function of Blancco’s

global Technical Support Team?

a: Our main function is to make sure

our customers can use Blancco product

solutions as efficiently as possible, and if

problems occur to help solve them as soon

as possible.

Q: what is your role within the

Technical Support Team?

a: My main role as manager of the team

is to learn if the customer is satisfied with

our services and how we can improve their

experience.

Q: how do global technical support

operations work at Blancco?

a: We divide the globe into three different

time zones—America, EMEA, and Asia

Pacific. The American zone covers North

and South America; the EMEA supports all

European countries, for example Finland,

Germany, France, the UK, and Benelux;

and Asian Pacific covers Japan, SE Asia and

Australasia. In this way we localize support

all over the world so that customers will be

supported in their own language, as much

as possible, in all of our major market

areas, and we can cover all time zones. The

advantage is that through our centralized

support system our offices can back each

other up during holidays or other busy

periods. Support is currently available in

eight different languages.

Q: what is the benefit of local support?

a: From the customer’s point of view our

support team is easier to contact when

he or she can communicate in his or her

own language, area and local time zone.

Nowadays, the human element is often

removed from technical support as IT

companies often automate or outsource

such services to a third party, but we make

sure that it’s always there. This is the key

advantage of our business strategy to localize

support, and our customers appreciate this.

Q: what is the goal of the Technical

Support Team?

a: Our goal is to have happy and satisfied

customers with effective data erasure

processes in place. We want to collect as much

feedback from our customers as possible

from the field. Ultimately, we will then be

able to report issues to our development

team to improve product quality.

Q: what are the main questions

or concerns customers have?

a: Most questions our customers ask

are not technical but process-related, or

Nowadays, the human element is

often removed from technical support

as IT companies often automate or

outsource such services to a third party,

but we make sure that it’s always there.

in other words, not on software issues,

but on the erasure process or how to

complete it.

Q: what would you like customers

to know about technical support?

a: We are here to help our customers

and to educate them on the usability of

our erasure solutions. We want to know if

customers are satisfied with our service.

We are more than happy to receive

feedback regarding our customer support

operations, and always open to new ideas

on how we can improve our services.

The best way to reach us is to fill out our

contact support form and a technical

support representative will contact you:

http://support.blancco.com ®

The north & east London commissioning

Support unit (cSu) utilizes Blancco data

erasure solutions to erase patient data

by selective data erasure on shared sever

systems and permanent erasure of Pcs,

laptops and servers. Blancco solutions are

helping the organization to secure data

and manage the lifecycle of its assets.

The North & East London CSU is a new

National Health Service (NHS) organization

which provides expert support and advice

to help clinical commissioners to deliver

improved health services to local populations

in the United Kingdom. The NHS is the world’s

largest publically funded health care system.

The North & East London CSU delivers an

extensive range of services from contracting

and analytics to finance and communications.

Following a major overaul and restructure

of the NHS in 2013, Commissioning Support

Units have been put in place to provide a

range of commissioning services to their

local NHS Trusts. The North & East London

CSU uses Blancco to decommission IT

equipment and for overall IT transition

support for their NHS Trust clients.

The North & East London CSU currently

utilizes a full range of Blancco product

solutions for their erasure needs including:

Blancco Management Console, Blancco 4.10

HMG, Blancco 4.10 Server, Blancco File, and

Blancco Support Package.

Blancco provided the North & East London

CSU with up front pre-sales technical

guidance and live product demos as well

as remote training when installing Blancco

Management Console. Since the initial set-

up, the organization has implemented various

customizations of the software including

remote deployment via MSI delivery and

automated erasure scheduling with the

Blancco Management Console also helping to

manage licenses and centralize reports.

With Blancco 4.10 HMG the organization

can erase data from servers, laptops and

PCs and Blancco 4.10 Server Edition allows

them to remotely erase servers. Blancco File

is used for selective erasure of patient data

in addition to erasing selective data from

shared servers systems with information

utilized by multiple trusts.

The North & East London CSU is required to

decommission servers that have been used

by previous NHS Trusts. Some of these trusts

used shared server systems for storing

information and, therefore, contained data

which had to be selectively erased in a

secure manner before being returned to the

ownership of the trust. Blancco File enabled

the organization to pick and choose which

information to permanently wipe and which

to retain to handle this complicated process.

Blancco has also been advising the North &

East London CSU on best practices for the

use of software and internal compliance

as well as selective erasure of patient data

from NAS servers.

With products tailored to the organization’s

needs, Blancco data erasure solutions have

helped the North & East London CSU to

implement a secure process for wiping

data in compliance with governmental

regulations in the UK. ®

Blancco has been advising the North

& East London CSU on best practices

for the use of software and internal

compliance as well as selective erasure

of patient data from NAS servers.

Data ErasurE nEws 3

Page 4: Data erasure news / issue 2

why erase data?IT assets pose a significant risk to organizations because of the large volumes of

confidential information stored on them. Data must be completely destroyed before IT

assets are disposed of, recycled, reused or donated.

BlanCCO expands GlOBally

Blancco is approved by:

Blancco opened a new subsidiary in

Brisbane, Australia in July. This opening not

only showcases our growth, but highlights

the need for proper data erasure to ensure

privacy worldwide.

Recent changes to Australia’s Privacy act will

go into effect next year prompting businesses

to ensure that they are in compliance with

the law and with international standards of

data privacy and security.

“With recent legislative changes in

Australia, it is more important than ever for

naTo Tüv-Süd nSM

report

Blancco also generates detailed reports

providing critical evidence of every

erasure.

erase

Blancco not only permanently erases all

data, including hidden and remapped

sectors…

BLancco’S unIQue era ProceSS

audit

These reports ensure the existence of

a comprehensive audit trail – a critical

requirement for compliance and

regulatory and legal auditing needs.

[email protected]

Copyright © 2013 Blancco Oy Ltd. All Rights Reserved. The information contained in this document represents the current view of Blancco Oy Ltd on the issues discussed as of the date of publication. Because of changing market conditions, Blancco cannot guarantee the accuracy of any information presented after the date of publication. This white paper is for informational purposes only. Blancco makes no warranties, express or implied, in this document. Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, no part of this document may be reproduced, stored in, or introduced into a retrieval system, or transmitted in any form or by any means (electronic, mechanical, photocopying, recording, or otherwise), or for any purpose, without the express written permission of Blancco.

For more information or to download our whitepapers,

please visit

www.blancco.com

One key advantage of Blancco's data erasure

solutions is that each erasure generates

a comprehensive and digitally-signed

report. Reports are critical to prove that the

erasure was actually performed as without

them there is no evidence that the erasure

actually took place. They can also help

collect details related to the erasure and

your organization´s IT sanitized assets.

Blancco’s reports are an essential part of

compliance, regulatory and legal auditing

requirements for your organization.

reports provide information about

the auditing process such as:

• Condition of the hardware

• Relevant serial numbers and asset tags

• Software details for license harvesting

• How and by whom the erasure was done

critical audit securityAll activities are logged in an erasure

report which ensures transparency and

gapless security prior to and during your

organization´s auditing process. These

reports include digital signatures for

maximum security and to avoid tampering.

compliance with industry regulations

Blancco's detailed reporting and auditing

information complies with industry

standards and regulations such as ISO

15408, ISO 27001, HIPAA, and PCI DSS. ®

organizations to have a partner like Blancco

to ensure they are managing data erasure

efficiently and securely,” says Karl gaines,

Managing Director of Blancco Australasia.

Blancco also established a subsidiary in

August in Berlin, Germany to serve our

governmental customers within the region.

“Blancco obtained BSI certification in March of

this year and now offers professional erasure

software to governmental institutions and

municipalities. Now we are positioned to serve

these customers in this region”, says Martin

Kaiser, Office Manager of Blancco Berlin.

the BeneFIts OF COmprehensIve repOrtInG

We have been growing in Central Europe

as more than fifty percent of the top

30-Fortune companies (DAX) in Germany

now use Blancco´s solutions as customers

demand more efficient and professional

data erasure management.

“The new Berlin office allows us to be in

the political hub in Germany and serve

selected customers in the Northeast

part, and to also expand into the Eastern

European market”, says Thomas wirth,

General Manager of Blancco Central

Europe. ®