<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Email management, storage and security for business email admins &#187; security encryption</title>
	<atom:link href="http://www.theemailadmin.com/tag/security-encryption/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.theemailadmin.com</link>
	<description></description>
	<lastBuildDate>Mon, 06 Sep 2010 13:21:42 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Portable storage devices need security controls</title>
		<link>http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/</link>
		<comments>http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 16:14:18 +0000</pubDate>
		<dc:creator>Dan Blacharski</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[security encryption]]></category>

		<guid isPermaLink="false">http://www.theemailadmin.com/?p=119</guid>
		<description><![CDATA[
			
				
			
		
Underscoring the logic behind the recent state laws that require encryption, a Department of Homeland Security report concludes that DHS itself does not have adequate security for portable electronic devices. The report issues recommendations for best practices in encryption, which are not only relevant to DHS, but for any business or government agency that has [...]<p>Liked this post? Get more <a href="http://www.theemailadmin.com">email management and administration</a> related news from TheEmailAdmin.com!<br/><br/><a href="http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/">Portable storage devices need security controls</a></p>
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.theemailadmin.com%2F2008%2F10%2Fportable-storage-devices-need-security-controls%2F" onclick="pageTracker._trackPageview('/outgoing/api.tweetmeme.com/share?url=http_3A_2F_2Fwww.theemailadmin.com_2F2008_2F10_2Fportable-storage-devices-need-security-controls_2F&amp;referer=');"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.theemailadmin.com%2F2008%2F10%2Fportable-storage-devices-need-security-controls%2F&amp;source=emailadm&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Underscoring the logic behind the recent state laws that require encryption, a Department of Homeland Security report concludes that DHS itself does not have adequate security for portable electronic devices. The report issues recommendations for best practices in encryption, which are not only relevant to DHS, but for any business or government agency that has portable devices that may contain personal information.</p>
<p>The report is based on an audit in which the Inspector General&#8217;s office identified several unauthorized data storage devices connected to internal servers and workstations. According to the audit, DHC has not fully complied with OMB requirements to control devices and protect against unauthorized access. Only five out of 11 agencies have implemented two-factor authentication, and none of them have controls to ensure that data extracts are erased within 90 days.</p>
<p><span id="more-119"></span></p>
<p>Portable storage devices do represent a major emerging security threat to any business or agency. Uncontrolled use of these portable devices, which may include flash drives, external hard drives, or even portable music players, according to the DHS report, &#8220;increases the risk of theft and mishandling of sensitive information when users insert their personal or unauthorized devices into their agencies&#8217; computers&#8217; Universal Serial Bus (USB) or FireWire ports.&#8221;</p>
<p>The portability of these devices, and the fact that more people have them on ordinary consumer devices such as the iPod, increases risk all around, and measures have to be taken to ensure that an employee can&#8217;t simply download data onto their music players.</p>
<p>The report highlights a few very startling breaches. In New Mexico, USB flash drives containing classified government information from Los Alamos National Laboratory was found at a contract employee&#8217;s home; and stolen military flash drives containing military records were found being sold at an Afghanistan street market.</p>
<p>The report recommends that all sensitive data stored on laptops and mobile devices be encrypted, that two-factor authentication be used for remote access, that a timeout feature for remote access be enabled, and that all data extracts of sensitive information be logged and that those extracts are erased within 90 days.</p>
<p>Liked this post? Get more <a href="http://www.theemailadmin.com">email management and administration</a> related news from TheEmailAdmin.com!<br/><br/><a href="http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/">Portable storage devices need security controls</a></p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand sexy-bookmarks-spaced sexy-bookmarks-bg-love">
<ul class="socials">
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/&amp;title=Portable+storage+devices+need+security+controls" rel="nofollow" class="external" title="Share this on Reddit" onclick="pageTracker._trackPageview('/outgoing/reddit.com/submit?url=http_//www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/_amp_title=Portable+storage+devices+need+security+controls&amp;referer=');">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/&amp;title=Portable+storage+devices+need+security+controls" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon" onclick="pageTracker._trackPageview('/outgoing/www.stumbleupon.com/submit?url=http_//www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/_amp_title=Portable+storage+devices+need+security+controls&amp;referer=');">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/" rel="nofollow" class="external" title="Share this on Technorati" onclick="pageTracker._trackPageview('/outgoing/technorati.com/faves?add=http_//www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/&amp;referer=');">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/&amp;title=Portable+storage+devices+need+security+controls" rel="nofollow" class="external" title="Share this on Mixx" onclick="pageTracker._trackPageview('/outgoing/www.mixx.com/submit?page_url=http_//www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/_amp_title=Portable+storage+devices+need+security+controls&amp;referer=');">Share this on Mixx</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/&amp;t=Portable+storage+devices+need+security+controls" rel="nofollow" class="external" title="Share this on Facebook" onclick="pageTracker._trackPageview('/outgoing/www.facebook.com/share.php?v=4_amp_src=bm_amp_u=http_//www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/_amp_t=Portable+storage+devices+need+security+controls&amp;referer=');">Share this on Facebook</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Portable+storage+devices+need+security+controls+-+http://b2l.me/q7b2k+&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!" onclick="pageTracker._trackPageview('/outgoing/twitter.com/home?status=Portable+storage+devices+need+security+controls+-+http_//b2l.me/q7b2k+_amp_source=shareaholic&amp;referer=');">Tweet This!</a>
		</li>
		<li class="sexy-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/&amp;title=Portable+storage+devices+need+security+controls&amp;summary=Underscoring%20the%20logic%20behind%20the%20recent%20state%20laws%20that%20require%20encryption%2C%20a%20Department%20of%20Homeland%20Security%20report%20concludes%20that%20DHS%20itself%20does%20not%20have%20adequate%20security%20for%20portable%20electronic%20devices.%20The%20report%20issues%20recommendations%20for%20best%20practices%20in%20encryption%2C%20which%20are%20not%20only%20rele&amp;source=Email management, storage and security for business email admins" rel="nofollow" class="external" title="Share this on LinkedIn" onclick="pageTracker._trackPageview('/outgoing/www.linkedin.com/shareArticle?mini=true_amp_url=http_//www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/_amp_title=Portable+storage+devices+need+security+controls_amp_summary=Underscoring_20the_20logic_20behind_20the_20recent_20state_20laws_20that_20require_20encryption_2C_20a_20Department_20of_20Homeland_20Security_20report_20concludes_20that_20DHS_20itself_20does_20not_20have_20adequate_20security_20for_20portable_20electronic_20devices._20The_20report_20issues_20recommendations_20for_20best_20practices_20in_20encryption_2C_20which_20are_20not_20only_20rele_amp_source=Email_management_storage_and_security_for_business_email_admins&amp;referer=');">Share this on LinkedIn</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.theemailadmin.com/2008/10/portable-storage-devices-need-security-controls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Digital Signatures and Security Encryption</title>
		<link>http://www.theemailadmin.com/2008/10/digital-signatures/</link>
		<comments>http://www.theemailadmin.com/2008/10/digital-signatures/#comments</comments>
		<pubDate>Sun, 19 Oct 2008 17:08:16 +0000</pubDate>
		<dc:creator>Mike Rede</dc:creator>
				<category><![CDATA[email security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[digital signatures]]></category>
		<category><![CDATA[security encryption]]></category>

		<guid isPermaLink="false">http://www.theemailadmin.com/?p=99</guid>
		<description><![CDATA[
			
				
			
		
I’ve spoken about Certificate Authorities and Certificates already. Remember that Certificates include: a public key, the owner and a digital signature. Well you’ve probably asked “what is a digital signature” and how do you “digitally sign” a certificate?
A digital signature is basically some value, a checksum. It is a data value based on a block [...]<p>Liked this post? Get more <a href="http://www.theemailadmin.com">email management and administration</a> related news from TheEmailAdmin.com!<br/><br/><a href="http://www.theemailadmin.com/2008/10/digital-signatures/">Digital Signatures and Security Encryption</a></p>
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.theemailadmin.com%2F2008%2F10%2Fdigital-signatures%2F" onclick="pageTracker._trackPageview('/outgoing/api.tweetmeme.com/share?url=http_3A_2F_2Fwww.theemailadmin.com_2F2008_2F10_2Fdigital-signatures_2F&amp;referer=');"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.theemailadmin.com%2F2008%2F10%2Fdigital-signatures%2F&amp;source=emailadm&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I’ve spoken about Certificate Authorities and Certificates already. Remember that Certificates include: a public key, the owner and a digital signature. Well you’ve probably asked “what is a digital signature” and how do you “digitally sign” a certificate?</p>
<p>A digital signature is basically some value, a checksum. It is a data value based on a block of data and a private key. The digital signature associates the data with the owner of a specific private key. You can be confident that the person indicated as the owner of a specific private key is not an imposter. You can safely open the email you received from the “certificated” owner then respond to that person, the owner, without fear or apprehension that the email will go to the wrong person. This also allows you to trust that the contents of the email were written and encrypted by the owner of the private key.</p>
<p>If you decrypt a message successfully with a particular public key – a key that was certified by means of a digitally signed certificate – then you can certain that it could have only been encrypted with the corresponding private key.</p>
<p>You can obtain a digital certificate from a commercial certification authority, such as VeriSign, Inc., or Thawte, or from your internal security administrator or Information Technology (IT) professional. Or, you can create a digital signature yourself using a tool such as Selfcert.exe. SelfCert.exe is installed as part of Office XP and can be found in C:\Program Files\Microsoft Office\Office10</p>
<p>Keep in mind that certificates you create yourself are considered unauthenticated and will generate a warning in the Security Warning box if the security level is set to High or Medium. Microsoft Office will only trust a self-signed certificate on a computer that has the private key for that certificate available which is usually only the computer that actually created the certificate, unless the private key was shared with other computers. Any macro projects that you create and sign by using such certificates are considered to be self-signed projects.</p>
<p>If you wish to use digital certificates that are signed by commercial certification authorities, such as VeriSign, Inc., you or your organization must submit an application to that authority. You can also get a list of Microsoft trusted third-party commercial certificate authorities at <a target="_blank" href="http://msdn.microsoft.com/en-us/library/ms995347.aspx" onclick="pageTracker._trackPageview('/outgoing/msdn.microsoft.com/en-us/library/ms995347.aspx?referer=');">http://msdn.microsoft.com/en-us/library/ms995347.aspx</a>.</p>
<p>Liked this post? Get more <a href="http://www.theemailadmin.com">email management and administration</a> related news from TheEmailAdmin.com!<br/><br/><a href="http://www.theemailadmin.com/2008/10/digital-signatures/">Digital Signatures and Security Encryption</a></p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand sexy-bookmarks-spaced sexy-bookmarks-bg-love">
<ul class="socials">
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.theemailadmin.com/2008/10/digital-signatures/&amp;title=Digital+Signatures+and+Security+Encryption" rel="nofollow" class="external" title="Share this on Reddit" onclick="pageTracker._trackPageview('/outgoing/reddit.com/submit?url=http_//www.theemailadmin.com/2008/10/digital-signatures/_amp_title=Digital+Signatures+and+Security+Encryption&amp;referer=');">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.theemailadmin.com/2008/10/digital-signatures/&amp;title=Digital+Signatures+and+Security+Encryption" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon" onclick="pageTracker._trackPageview('/outgoing/www.stumbleupon.com/submit?url=http_//www.theemailadmin.com/2008/10/digital-signatures/_amp_title=Digital+Signatures+and+Security+Encryption&amp;referer=');">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.theemailadmin.com/2008/10/digital-signatures/" rel="nofollow" class="external" title="Share this on Technorati" onclick="pageTracker._trackPageview('/outgoing/technorati.com/faves?add=http_//www.theemailadmin.com/2008/10/digital-signatures/&amp;referer=');">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.theemailadmin.com/2008/10/digital-signatures/&amp;title=Digital+Signatures+and+Security+Encryption" rel="nofollow" class="external" title="Share this on Mixx" onclick="pageTracker._trackPageview('/outgoing/www.mixx.com/submit?page_url=http_//www.theemailadmin.com/2008/10/digital-signatures/_amp_title=Digital+Signatures+and+Security+Encryption&amp;referer=');">Share this on Mixx</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.theemailadmin.com/2008/10/digital-signatures/&amp;t=Digital+Signatures+and+Security+Encryption" rel="nofollow" class="external" title="Share this on Facebook" onclick="pageTracker._trackPageview('/outgoing/www.facebook.com/share.php?v=4_amp_src=bm_amp_u=http_//www.theemailadmin.com/2008/10/digital-signatures/_amp_t=Digital+Signatures+and+Security+Encryption&amp;referer=');">Share this on Facebook</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Digital+Signatures+and+Security+Encryption+-+http://b2l.me/q35xu+&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!" onclick="pageTracker._trackPageview('/outgoing/twitter.com/home?status=Digital+Signatures+and+Security+Encryption+-+http_//b2l.me/q35xu+_amp_source=shareaholic&amp;referer=');">Tweet This!</a>
		</li>
		<li class="sexy-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.theemailadmin.com/2008/10/digital-signatures/&amp;title=Digital+Signatures+and+Security+Encryption&amp;summary=I%E2%80%99ve%20spoken%20about%20Certificate%20Authorities%20and%20Certificates%20already.%20Remember%20that%20Certificates%20include%3A%20a%20public%20key%2C%20the%20owner%20and%20a%20digital%20signature.%20Well%20you%E2%80%99ve%20probably%20asked%20%E2%80%9Cwhat%20is%20a%20digital%20signature%E2%80%9D%20and%20how%20do%20you%20%E2%80%9Cdigitally%20sign%E2%80%9D%20a%20certificate%3F%0D%0A%0D%0AA%20digital%20signature%20is%20basic&amp;source=Email management, storage and security for business email admins" rel="nofollow" class="external" title="Share this on LinkedIn" onclick="pageTracker._trackPageview('/outgoing/www.linkedin.com/shareArticle?mini=true_amp_url=http_//www.theemailadmin.com/2008/10/digital-signatures/_amp_title=Digital+Signatures+and+Security+Encryption_amp_summary=I_E2_80_99ve_20spoken_20about_20Certificate_20Authorities_20and_20Certificates_20already._20Remember_20that_20Certificates_20include_3A_20a_20public_20key_2C_20the_20owner_20and_20a_20digital_20signature._20Well_20you_E2_80_99ve_20probably_20asked_20_E2_80_9Cwhat_20is_20a_20digital_20signature_E2_80_9D_20and_20how_20do_20you_20_E2_80_9Cdigitally_20sign_E2_80_9D_20a_20certificate_3F_0D_0A_0D_0AA_20digital_20signature_20is_20basic_amp_source=Email_management_storage_and_security_for_business_email_admins&amp;referer=');">Share this on LinkedIn</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.theemailadmin.com/2008/10/digital-signatures/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
