drj logo
drj logo

Welcome to DRJ

Already registered user? Please login here

Create new account
(it's completely free). Subscribe

x

Keeping up with USB Encryption Technology to Keep your Data Safe

USBThere are several articles being written today concerning transporting business continuity (BC) and/or disaster recovery (DR) plans on USB flash memory drives. There are many valid reasons to get away from carrying paper plans, or plans that have been written to CD. One of the major reasons is that there is a good chance the document will end up in the trunk of a car shortly after receiving them. This seems to be an acceptable solution until someone needs a handy wipe after changing a tire or checking the oil. Time does not treat paper plans well when stored in an automobile. BC/DR plans stored on CDs create their own set of problems. The most likely place for a CD to end up when being stored in an automobile is in the glove compartment. Temperatures inside a closed automobile can easily reach 130(F) degrees on a summer day. Temperatures in that range are not conducive to the longevity of CDs. I have seen CDs that have curled up and taken the shape of a Ruffles potato chip. This is not a good solution in either case for when your plan is needed.

Transferring the BC/DR plans to a USB drive can resolve both of the above problems. The USB devices are not as susceptible to the heat such as CDs and storage concerns are not a major problem due to their size. I have seen team members go so far as using silicone adhesive to glue the USB to the underside of the truck lid. The USB was safe from getting mixed up with the other items within the trunk of the car and was easily accessible if needed. As they say, “Whatever works.”

If your company decides to distribute and store plans on USB drives, the next question/consideration should be: “How to handle security on the USB drives?” This is a much broader question than most people would think, and there are a few considerations and three major security options to choose from.

Unfortunately, there is no “one size fits all” regarding security requirements when using USB drives. But here are a few topics to consider when starting the evaluation process.

Some of the considerations are:

  • How security is implemented on the USB drive
  • Determine the classification of the data stored
  • Evaluate the consequences if the data was released or even possibly released outside the company
  • Evaluate user interface program that comes with the secure drive
  • Review cost of the USB drive

There are three major types of configurations on secure USB drives.

The first type is the generic USB drive with security software as an add-on.

The second and third types are very close in design with both having an on board security processor that is part of the USB drive itself. The major difference between the second and third category is the number of user accessible partitions on the secure drive.

The second type of drive has two user partitions; one being always accessible and unencrypted while the other partition is secured using encryption.

The third type of configuration has only a single user partition that is secured using encryption.

(NOTE: Most of the secure USB drives also have a read only partition that is used by the manufacturer to store the user interface software. This read-only partition is not pertinent to our discussions.)

The first type of secure USB drive is the simplest of all the solutions with a generic USB drive combined with security software as an add-on. These are the USB drives that can be purchased at any of your local electronic retailers. Some of the USB drives come pre-installed with security software. For the USB drives that do not have a pre-installed security software program, there are many downloadable encryption packages for free off of the web. For those people that already have a copy of WinZip on your computer, there is an AES encryption process built into the standard package. This WinZip encryption process also works very well.

While the generic drives with add-on encryption software do well in many cases, there are USB drives that provide a higher level of security. The second and third types of drives contain their own onboard security processor along with the standard memory storage. This onboard processor allows for a much higher level of security to be implemented. Many of these secure USB drives have been developed to meet the FIPS 140-2 level-two certification standards. FIPS 140-2 is a NIST (National Institute of Standards and Technology) accreditation process for cryptography modules. One of the major security enhancements of the secure USB drives with the on-board security processor is that password comparisons are performed by the processor on the USB drive, not in the memory of the PC. At no time is the secure USB password or password hash copied to the memory of the PC. Therefore, any malware installed on the PC will not have the ability to eavesdrop on the password/hash comparison process.

There is one major difference in the way security volumes are defined on the second and third types of secure USB drives. The second type of secure drive allows the user to store un-encrypted data, as well encrypted data on the same physical drive, but in two separate partitions. This is accomplished by the USB vendor defining two separate user accessible partitions. This can be a good or bad feature, depending on your requirements. The third type of secure drive has what I would call a single mandatory encryption volume. In this implementation, any and all user data that is placed on the drive is required to be stored on an encrypted partition. There is no possible way to store un-encrypted data on this type of USB device. Sometimes this security configuration has been referred to as “always on.”

Another advantage of the secure UBS drives is that they are usually physically built much stronger than the standard drives. Many have robust metal cases that will tolerate tremendous amounts of abuse. There are a few models of secure USB drives that have all of the electronic components encased in an epoxy compound. This provides a water tight environment (MIL-STD-810F) for the electronics as well as making it impossible to access the internal electronics without causing damage. There are a few models that incorporate fingerprint readers into the drive for those so inclined to that type of technology. The downside on using these secure drives with onboard security processors is price. A USB drive can run anywhere from $50 to $100 for a 1GB secure drive and up to $300 for a 32GB drive that implements the extra hardware features.

Besides knowing the three types of secure USB drive configurations, knowing the data classifications for your plans is also important. Most plans contain sensitive data such as lists of critical people, home phone numbers, vendor account numbers, etc. Much of this data would be classified as Sensitive, but Unclassified. Now consider what the effects would be if the data were to be disseminated outside the company. For example, let’s say that your plans have sensitive information, but not any data that could cause financial or reputational harm to the company. If this information were to be revealed, the effects would probably be minor. The data should therefore be encrypted, but you may not need to go the extra effort to purchase the hardware secure drives.

I have also reviewed BC/DR plans that have contained financial account codes along with the needed passwords and IP addresses of sensitive financial systems. This is the type of information that could cause severe impact if released inadvertently. This type of data would most likely be classified as company confidential or secret. If your company keeps confidential information in their plans, then release of this information could cause considerable financial and/or reputational damage to the company. In this case, you may be able to justify the need and additional costs for the secure USB drives with the on-board security processors.

Another task that should be considered when evaluating secure USB drives is to evaluate the user interface program supplied with the drive. For reasons unknown, some of these user interface programs supplied with the drives are less than user friendly. A few of the drives are supplied with user interface programs that are convoluted and non-intuitive in design. Other companies have taken the time to do the interfaces right and make them intuitive and very user friendly. I cannot stress this evaluation task enough. There are great differences in the quality of the user interface programs packaged with the secure drives.

In the case of a lost USB drive that contains critical financial or business data, the first question asked most likely will be, “Was the information encrypted?” Following will be the second likely question, “Was there any way that the data could have been stored on the USB drive in an unencrypted format?” If the data was stored on a single partition secure drive, then you are assured that the data was encrypted, and just as important, there was no way to carry unencrypted data on the drive by mistake. The financial impact of a lost USB drive will be contained to the cost of a replacement. All of a sudden, that $70 USB drive looks to be very cost effective when compared to value of the data that is contained within. In situations where critical financial information is stored on the USB drive, I would recommend the use of the hardware assisted secure drive with a single partition. If the USB drive is lost, everyone including your company legal staff can be assured that no confidential data could be extracted off the drive and made public. When using the two partitions secure drive, there is always the remote possibility that the critical data may be placed on the non-encrypted partition by mistake. This is the risk associated with using the secure USB drives that have multiple user accessible partitions. Your company may not want to take that risk.

There are several good USB drives on the market that provide on-board hardware or software encryption. In many cases, the prospective owner may receive an initial price shock. But be sure to consider what the total costs could be if your company’s confidential information were to be leaked to the public. There is definitely a need for secure USB drives in today’s market.

Jeffrey Blackmon, CBCP, CISSP, MBCI, ITIL(F) has a diverse international background that includes work in the financial industry, overseas petroleum industry, government to government military contracts, pharmaceutical industry and the US federal government. He is owner/president of Strategic Continuity Solutions, LLC and can be reached at Jeff@Strat-Con-Sol.com.

Latest News
DRJ HOT ITEMS
Webinar Spotlight
Fetching Upcoming Webinars...
Journal Categories

AI: Automation & Innovation

Business Continuity Management

Crisis Management & Emergency Response

Cyber Resilience & IT Disaster Recovery

Leadership: Culture & Workforce Resilience

Operational Resilience

Risk Management & Quantification

Sector-Specific & Critical Infrastructure Resilience

Supply Chain & Third-Party Resilience

Governance: Compliance & Regulatory Readiness

Incident Management & Response Coordination

Resilience Strategy & Program Maturity

Data Protection: Backup & Recovery

Exercises: Testing & Scenario Planning

Emerging Threats: Geopolitical & Climate Risk

Contact Us

Newsletter

The Journal, right in your inbox.