Technology Get the latest on technology, electronics and software…

Data Security

Thread Tools
 
Old Dec 21, 2012 | 10:20 AM
  #1  
stogie1020's Avatar
Thread Starter
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Data Security

OK, hypothetical, I am researching some solutions and am looking for any of your recent experiences solving portions of this problem:

Setup:

Office has 20-40 workstations (mix of Laptop and Desktop)

Office is a high tech firm with lots of collaboration.

"Subnetworks" exist where some docs reside on one or more networked machines but are not networked with others. I.E. Production or R+D staff may have 6 workstations and management may have 8, but to get some files from production to management, they are manually copied to USB or email and then transported as they are not all linked for file sharing and data is not centrally stored.

Office has many sensitive documents and some secret docs. All are used regularly by portions of staff on the workstations.

Issue:

Office would like to accomplish the following as best as possible:

- Restrict use of USB devices to ONLY company authorized ones
- Restrict use of some or all company files to ONLY on company workstations
- Allow for non-overly cumbersome collaboration of documents with a higher level of auditing insofar as who accessed what, when
- Prevent the spread of data to non-company workstations via email and USB drives

I realize there is probably no "one size fits all solution" but I am looking for any suggestions that may help accomplish some or all of the above.
Reply
Old Dec 21, 2012 | 10:27 AM
  #2  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,973
Likes: 11,762
From: Florida
Dynamic Access Control in Server 2012

http://www.windowsecurity.com/articl...rver-2012.html
Reply
Old Dec 21, 2012 | 10:45 AM
  #3  
underdog's Avatar
I am #76,361,211,935
 
Joined: Nov 2001
Posts: 1,285
Likes: 344
From: Ottawa,Ontario
Probably massive overkill but could they purchase a (DoD) 5015.02-STD certified
Records Management / Content Management system to use in conjunction with a strict
outbound email filters?
Reply
Old Dec 21, 2012 | 02:04 PM
  #4  
Professor's Avatar
Карты убийцы
 
Joined: Apr 2003
Posts: 8,264
Likes: 125
From: Cochabamba, Bolivia
Ask somebody in the DOR of South Carolina and see how 4 million people had their id stole.
Reply
Old Dec 21, 2012 | 06:02 PM
  #5  
Ken1997TL's Avatar
Senior Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: May 2003
Posts: 45,641
Likes: 2,335
From: Better Neighborhood, Arizona
Originally Posted by #1 STUNNA
Dynamic Access Control in Server 2012

http://www.windowsecurity.com/articl...rver-2012.html
Brilliant
Reply
Old Dec 21, 2012 | 06:34 PM
  #6  
stogie1020's Avatar
Thread Starter
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Originally Posted by #1 STUNNA
Dynamic Access Control in Server 2012

http://www.windowsecurity.com/articl...rver-2012.html
I need to read up on this a bit more. Looks very promising, thanks Daniel.

Any idea what controls would be in place if a company were using this and someone did manage to get a doc out of the system? Would the doc be un-openable?
Reply
Old Dec 21, 2012 | 08:22 PM
  #7  
nfnsquared's Avatar
Race Director
 
Joined: Dec 2003
Posts: 12,521
Likes: 1,824
From: MAGA country
Dude, pretty clear to me that you're in over your head. I'd punt, just saying... Don't hate on me for honesty.
Reply
Old Dec 21, 2012 | 09:22 PM
  #8  
HEAVY_RL's Avatar
Suzuka Master
iTrader: (1)
 
Joined: Nov 2008
Posts: 7,123
Likes: 1,045
From: RVa
he is only hypothetically over his head.
Reply
Old Dec 21, 2012 | 10:41 PM
  #9  
Scottman111's Avatar
1919
 
Joined: Mar 2005
Posts: 21,467
Likes: 162
Originally Posted by nfnsquared
Dude, pretty clear to me that you're in over your head. I'd punt, just saying... Don't hate on me for honesty.

Or he's doing some research to come up with the best solution?

Don't have to tell you that every solution doesn't just appear in your mind. And if an idea did pop up right away, I'd still research the issue further to see what else is out there
Reply
Old Dec 21, 2012 | 11:15 PM
  #10  
Ken1997TL's Avatar
Senior Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: May 2003
Posts: 45,641
Likes: 2,335
From: Better Neighborhood, Arizona
Originally Posted by nfnsquared
Dude, pretty clear to me that you're in over your head. I'd punt, just saying... Don't hate on me for honesty.
May a thousand camel spiders infest your mother's tent!
Reply
Old Dec 21, 2012 | 11:33 PM
  #11  
nfnsquared's Avatar
Race Director
 
Joined: Dec 2003
Posts: 12,521
Likes: 1,824
From: MAGA country
Stogie,

Think about your liability and reputation if you fail....You are just starting to get back on your feet with the new business.

I wouldn't risk it unless you are absolutely sure you can do it right, without having the "deer in the headlights" look in your eyes when problems arise (and they will, it happens to everyone) during the implementation.
Reply
Old Dec 21, 2012 | 11:38 PM
  #12  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,973
Likes: 11,762
From: Florida
Yeah I can't answer that question, I'd like to know myself if you find out. My guess would be that it would be unopenable on an unapproved device.

Last edited by #1 STUNNA; Dec 21, 2012 at 11:48 PM.
Reply
Old Dec 21, 2012 | 11:50 PM
  #13  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,973
Likes: 11,762
From: Florida
Seems like you'd need to be running server 2012 as the main domain controller so if the network is already setup running an older version of AD then you might have to make a new domain. I don't think domains are upgradeable
Reply
Old Dec 21, 2012 | 11:56 PM
  #14  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,973
Likes: 11,762
From: Florida
I also wonder about copying and pasting from the document. If that's blocked can you still do it within different parts of the same document?

Also what about screenshots, might want to find a way to disable that too. Then maybe forbid cameras and camera phones too if they're hella paranoid.
Reply
Old Dec 22, 2012 | 10:54 AM
  #15  
stogie1020's Avatar
Thread Starter
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Originally Posted by nfnsquared
Dude, pretty clear to me that you're in over your head. I'd punt, just saying... Don't hate on me for honesty.
Dude, relax.

A. It's hypothetical
B. I do not generally do network installs or setups (I use contractors), so while I may get paid to advise people on possibilities, I do not do implementation in this realm.
Reply
Old Dec 22, 2012 | 10:57 AM
  #16  
stogie1020's Avatar
Thread Starter
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Originally Posted by Scottman111
Or he's doing some research to come up with the best solution?

Don't have to tell you that every solution doesn't just appear in your mind. And if an idea did pop up right away, I'd still research the issue further to see what else is out there

Originally Posted by Ken1997TL
May a thousand camel spiders infest your mother's tent!

Originally Posted by #1 STUNNA
I also wonder about copying and pasting from the document. If that's blocked can you still do it within different parts of the same document?

Also what about screenshots, might want to find a way to disable that too. Then maybe forbid cameras and camera phones too if they're hella paranoid.
New User Dennis Ho PM'ed me (thanks, your mail box is full) indicating he works for a company called Devicelock that seems to address some of these issues as well (Screen capture, copy paste, etc.). I know nothing about the company, but here is a link: www.devicelock.com. Might be interesting to talk to a few folks who have used this...
Reply
Old Dec 22, 2012 | 03:06 PM
  #17  
nfnsquared's Avatar
Race Director
 
Joined: Dec 2003
Posts: 12,521
Likes: 1,824
From: MAGA country
Interesting... not exactly cheap up front, but could prove priceless even in the short run...

Trend also has a tool:

http://www.trendmicro.com/us/enterpr...uct/index.html

and pretty sure Symantec as well...

Last edited by nfnsquared; Dec 22, 2012 at 03:16 PM.
Reply
Old Dec 22, 2012 | 03:12 PM
  #18  
Whiskers's Avatar
Go Giants
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Aug 2004
Posts: 70,003
Likes: 1,260
From: PA
Netnanny?
Reply
Old Dec 22, 2012 | 05:18 PM
  #19  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
These things are all great until you piss off the one guy that knows the master admin password.
Reply
Old Dec 22, 2012 | 06:19 PM
  #20  
stogie1020's Avatar
Thread Starter
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Originally Posted by doopstr
These things are all great until you piss off the one guy that knows the master admin password.
It's OK. Password is probably "password"
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Yumcha
Automotive News
70
Dec 7, 2020 05:39 PM
Yumcha
Automotive News
4
Aug 15, 2019 12:58 PM
bearingman07936
5G TLX Audio, Bluetooth, Electronics & Navigation
6
Jan 7, 2016 03:22 PM
eastcoastguy
3G TL (2004-2008)
25
Oct 29, 2015 03:00 PM
MilanoRedDashR
3G TL (2004-2008)
5
Sep 27, 2015 10:15 PM




All times are GMT -5. The time now is 10:29 AM.