Wednesday, 20 May 2009

Alcatel-Lucent Expands Encryption, VPN Capabilities of OmniAccess 3500 Nonstop Laptop Guardian

Alcatel-Lucent (Euronext Paris: ALU) (NYSE: ALU) today announced new data encryption and virtual private network (VPN) features for its OmniAccess 3500 Nonstop Laptop Guardian (NLG) laptop security and management system that improve the security of data residing on laptops.

Invented by Bell Labs and incubated by Alcatel-Lucent Ventures, the OmniAccess 3500 NLG, is the first comprehensive solution that reduces laptop security breaches, delivering 'always-on' connectivity for visibility and control over laptops on a 24/7 basis -- even when the laptop is turned off.

The features are available in a new release of the OmniAccess 3500 software and include:

--  Full hard-disk encryption integration framework -- All full disk
encryption (FDE) vendors are now able to integrate with the OmniAccess 3500
NLG. This will enhance vendor encryption solutions with the capability to
remotely manage encryption keys and provide a second-factor of
authentication when the laptop is turned off or is offline. Keys and second-
factor authentication are stored on the NLG card and can be remotely
deleted to make the hard disk inaccessible in case of a lost or stolen
laptop. This capability closes an important security loop, as laptop data
can not be accessed without the management controls enforced by the
OmniAccess 3500 NLG. Together with NLG's GPS location capabilities --
security and manageability are now upgraded.

-- Industry first Active Smartcard for Windows and pre-boot
authentication -- Many FDE solutions require a Smartcard to be used for
encryption keys -- a solution that can't be updated over a network. The NLG
now emulates a Smartcard, but allows IT administrators to create,
invalidate, revoke, and reissue the Smartcard or its PIN securely over the
air and on the fly for faster response and lower administration costs.

-- SSL VPN access -- This capability gives NLG users another secure
option for using a VPN while visiting a customer or partner location. In
addition to the built-in IPSec VPN, NLG now supports secure switch over to
web-based SSL VPN if used by customers' IT. This capability keeps the
always-on VPN solution that defines the NLG solution intact, while allowing
end-users the freedom to use SSL when needed.

-- Multiple user support -- This option allows multiple end-users to
share a single NLG-protected laptop, without compromising security.

-- Mid-range gateway -- Alcatel-Lucent has scaled the back-office NLG
gateway to fit the needs of companies with up to 500 NLG users. This new
server supports Business Partner and carrier demand to provide a cost-
effective solution for these mid-sized companies.

"NLG continues to innovate in the space of mobile security. The interactive Smartcard capabilities are truly unique in the market," said Tom Burns, COO of enterprise activities for Alcatel-Lucent. "Our customers are reacting very positively to the NLG and we believe these new features help to ensure that the NLG remains the most comprehensive endpoint security solution on the market. With our new mid-range gateway (at a reduced cost), we have put the product within reach of mid-sized customers and have dramatically increased our addressable market."

"With these and previous new feature developments in the OmniAccess 3500 NLG, Alcatel-Lucent has elevated NLG's attractiveness," states Michael Suby, Director of Stratecast (a Division of Frost & Sullivan). "These enhancements deliver to enterprises what they need the most: flexibility to tailor security technologies to meet their unique device and information protection objectives."

With this solution, IT departments are able to enforce policies for compliance, protection and recovery of stolen devices, and deliver patches and upgrades to an increasingly mobile workforce anytime, anywhere, thereby increasing productivity and efficiency. In addition to other channel partners, Alcatel-Lucent is working with Sprint to deliver the OmniAccess 3500 NLG as part of a complete wireless enterprise solution.

Availability

OmniAccess 3500 Nonstop Laptop Guardian solution includes PCMCIA cards for laptops and a management server. The product is packaged with 3G services and sold through wireless service providers and Alcatel-Lucent Business Partners. Nonstop Laptop Guardian is currently available through Alcatel-Lucent channels in North America, including Sprint, and will launch in Europe in Q3 2008.

About the OmniAccess 3500 Nonstop Laptop Guardian

The core technology of the OmniAccess 3500 NLG consists of a secure, always-on computing system that is available for IT even when the laptop is turned off. Residing on a 3G broadband PCMCIA data card which includes a separate secure operating system and battery, which operates with any broadband network, including 3G, Ethernet or WiFi. When a laptop is connected to a network, the card seamlessly transitions connectivity to the corporate network through automatic VPN capabilities, ensuring that all traffic, regardless of data connection type, passes directly through the corporate network's protections, filters and policy managers before accessing the Internet.

Sunday, 10 May 2009

MoD Data Security Report Released

Four MoD laptops were stolen between 2004 and 2008According to a investigation carried out for the Ministry of Defence by Sir Edmund Burton, new recruits to the armed forces belonging to the so-termed “Facebook generation” failed to take adequate data security measures.

MoD Laptop Thefts

Sir Edmund, Information Advisory Council Chairman, was asked to look into the issue of security following the theft of a number of MoD laptops, of which one occurred at the beginning of 2008.

In a stark report, Burton asserted that the MoD’s Cold War data security ethics had disappeared, with “little awareness” of the importance of security within its employees.

Consequently, a significant event involving security had, he said, been “inevitable.”

The 2008 laptop theft occurred from a vehicle parked in Edgbaston, Birmingham, UK. On it were records relating to 600,000 service personnel and armed forces applicants.

It was subsequently discovered that, between 2004 and 2008, a total of four laptops had been stolen in similar circumstances.

MoD Data Protection Act Obligations

Combined, said Sir Edmund, the losses pointed to a “failure of supervision”, with a “very limited understanding“ of the ministry’s obligations in connection with the Data Protection Act.

"During the Cold War, awareness of real security was ingrained in individuals and organisations", the report stated. "Audit, inspection and compliance regimes were rigorously underpinned by codes of discipline.

"These well-developed processes and procedures have not been translated, effectively, into the information age.

"Generally, there is little awareness of the current, real, threat to information, and hence to the department's ability to deliver and support operational capability.

"Consequently, there can be little assurance that information is being effectively protected."

New Military Recruits

Sir Edmund highlighted the “Facebook generation” that new recruits belonged to.

Young British military personnel, he said, were accustomed to the “rapid and often uninhibited exchange of information."

“At work, this behaviour must be tempered by common sense and sound judgment, informed by data protection practice, and the particular concerns of MoD work.

"However, returning to the strict information control of the type applied to paper documentation of 15 or more years ago is not considered practical in the modern working and cultural environment."

Personal Record Access

The MoD, said Burton, had sought to implement up-to-date working methods, especially within Personnel, with better access to personal records.

However, "one consequence of embracing this new data sharing culture has been a decline in overall departmental security practice.”

Senior officials, Sir Edmund wrote, "shared a concern that the younger generation of MoD staff are not inculcated with the same culture of protecting information as their counterparts from previous generations."

In all, 51 suggestions for improvement were listed, among them, the setting-up of a “coherent system of censure and punishment" for those responsible for losing or compromising the security of personal information – a system flexible enough to apply to different severities of loss.

Source – Armed Forces International’s Political Correspondent

Friday, 1 May 2009

Bosses' insolvency data is stolen

Laptop
Police are investigating the burglary, which occurred on 28 August

A laptop computer containing personal details of 385 former directors of insolvent companies has been stolen, the Insolvency Service has said.

It has written to those it believes may have been affected by the theft of equipment from its Manchester offices.

One of four laptops stolen from the government agency contained information on the directors from 122 firms.

This loss is the latest in a long line of cases where confidential information has been lost or stolen.

Greater Manchester Police are investigating the burglary, which happened on 28 August.

Those affected by the theft include former company directors, insolvency practitioners and people who were named in documents, including creditors, complainants, investors and employees.

The Insolvency Service said 385 ex-company directors had been affected and also about 150 people with a connection to the firms.

Information on the company directors included name, address, date of birth and occupation. No bank account details were held.

In relation to the creditors, complainants and employees, the data included name, address, and bank account details in a small number of cases.

Telephone helplines

A spokeswoman for the Insolvency Service, which investigates corporate failures to see if particular company directors were at fault, said none of the insolvent companies concerned was a "household name".

She said most of them were "small and medium-sized companies".

Several dedicated telephone helplines have been set up and anyone who has concerns should go to the Insolvency Service website to find the appropriate contact number.

A statement from the Insolvency Service said: "The information consisted of documents sent to the Insolvency Service by insolvency practitioners who act as administrators, receivers or liquidators of insolvent companies.

"The documents, which are required to be sent by law, included information about the activities of company directors which the insolvency practitioner considers may give cause for concern."

Earlier this month, the government confirmed that a portable computer hard drive holding details of up to 5,000 justice system employees had been lost in July 2007.

In August, Home Office contractor PA Consulting admitted losing a computer memory stick containing information on all 84,000 prisoners in England and Wales.

And in June, a senior intelligence officer from the Cabinet Office was suspended after documents were left on the seat of a commuter train from London Waterloo.

The seven-page file, classified as "UK Top Secret", contained a report entitled "Al-Qaeda Vulnerabilities" and an assessment of the state of Iraq's security forces. A passenger later handed the file to the BBC.

Saturday, 25 April 2009

MoD laptop stolen from McDonalds

Laptop, Science Photo Library
MoD staff are banned from taking unencrypted laptops out of offices

The Ministry of Defence says a laptop has been stolen from a member of the military as he was eating in McDonalds.

The computer was taken from under the Army captain's chair, near the MoD's Whitehall headquarters on 1 April, according to the Sun newspaper.

The MoD said the data on the laptop was not sensitive, and was fully encrypted.

It comes after a laptop holding details of 600,000 people who applied to join the armed forces was stolen from a car in Edgbaston, Birmingham, in January.

A Ministry of Defence spokesman said that police were investigating the theft.

It comes after the government tightened the rules on employees taking computers out of work.

Whitehall staff are now banned from taking unencrypted laptops or drives containing personal data outside secured office premises.

Source - BBC News

Monday, 20 April 2009

Blears PC loss - officials blamed

Hazel Blears
The break-in took place at Hazel Blears Salford office on 14 June

Information on a computer stolen from Communities Secretary Hazel Blears' office had been sent in breach of data security rules, it has emerged.

The Communities and Local Government department admitted its officials had "not fully" complied with guidance on handling sensitive data.

Its top civil servant Peter Housden said "no damage had been done" as the documents were not secret.

Manchester Police are investigating the theft from Ms Blears' Salford office.

The computer contained a combination of constituency and government information relating to defence and extremism.

I have instructed my officials that departmental procedures are now strengthened to ensure this does not happen again
Peter Housden
Communities and Local Government

Mr Housden said in a statement: "It is clear that papers have been sent to Hazel Blears in a way that is not fully consistent with the departmental guidance.

"Thankfully no damage has been done since the documents sent to her were not classified as secret or top secret. And in any event the computer was password protected.

"I have instructed my officials that departmental procedures, guidance, and the awareness and accessibility of that guidance, are now strengthened to ensure this does not happen again.

"I take full responsibility for ensuring this is done."

Confidential document

Department sources suggested that no officials were likely to lose their job over the breach, but did not rule out disciplinary action.

This is the latest in a series of security breaches that have embarrassed the government. Last week a senior Cabinet Office official was suspended for leaving top secret documents on a train.

Another file of documents, including one restricted one, was found on another train last week as well.

The news that a government minister may have been directly responsible for the loss of data relating to extremism is extremely alarming
Dominic Grieve
Shadow home secretary

After Gordon Brown was informed of the theft from Ms Blears' office, he told cabinet ministers to ask their civil servants to remind staff of the importance of enforcing procedures on the treatment of sensitive information.

Shadow home secretary Dominic Grieve called for Parliament to be told "exactly how and why this has occurred".

"The news that a government minister may have been directly responsible for the loss of data relating to extremism is extremely alarming," he said.

The stolen computer is understood to have contained one confidential document relating to the housing market from March this year, as well as other restricted documents.

But the documents did not contain any information that could compromise national security.

They also contained information that shows Cabinet members disagree over the government's proposed planning laws.

'Alarm'

Restricted government documents should not be held on a personal computer.

A government spokesman said the machine contained material from the Department for Communities and Local Government and details relating to her constituency work.

He insisted no personal details were among the departmental information.

"There was a break-in at the constituency office of Hazel Blears on the afternoon of Saturday, 14 June. Hazel was not there at the time, " the spokesman said.

"The thief broke in through a window, triggering the building's security alarm. A PC was stolen. Nothing else was taken.

"We understand the building's security staff arrived within minutes.

"The PC was primarily used for Hazel's constituency business and contained some details of her constituency work."

The spokesman said "none of the departmental material included sensitive personal data about the public or would be of use to criminals".

He added: "The PC did not contain any secret or top secret information and the contents of the PC are protected and clearly this is now subject to a routine police investigation."

Source - BBC News