Garage Sale Forensics: Data Discovery Through Discarded Devices

Size: px
Start display at page:

Download "Garage Sale Forensics: Data Discovery Through Discarded Devices"

Transcription

1 Garage Sale Forensics: Data Discovery Through Discarded Devices John Michael Wright Mike County of Butte Session ID: DAS-403 Session Classification: Intermediate

2 Objectives - What I hope you take away Better awareness of media device threats 2

3 Objectives - What I hope you take away Better awareness of media device threats The Importance of a policy 3

4 Objectives - What I hope you take away Better awareness of media device threats The Importance of a policy Understanding that devices are easy to get 4

5 Objectives - What I hope you take away Better awareness of media device threats The Importance of a policy Understanding that devices are easy to get Introduction to cheap and free tools and methods 5

6 Objectives - What I hope you take away Better awareness of media device threats The Importance of a policy Understanding that devices are easy to get Introduction to cheap and free tools and methods Preventing data loss is easy and fun 6

7 The Data 7

8 The Data Electronic Data Storage Devices Defined 8

9 The Data Electronic Data Storage Devices Defined Statistics 9

10 The Data Electronic Data Storage Devices Defined Statistics Where 10

11 The Data Electronic Data Storage Devices Defined Statistics Where Who 11

12 The Data Electronic Data Storage Devices Defined Statistics Where Who What 12

13 The Data Electronic Data Storage Devices Defined Statistics Where Who What Passwords 13

14 The Data Electronic Data Storage Devices Defined Statistics Where Who What Domain Information 14

15 The Data Electronic Data Storage Devices Defined Statistics Where Who What Domain Information 15

16 The Data Electronic Data Storage Devices Defined Statistics Where Who What Financial Data 16

17 The Data Electronic Data Storage Devices Defined Statistics Where Who What Health 17

18 The Data Electronic Data Storage Devices Defined Statistics Where Who What Other 18

19 The Data Electronic Data Storage Devices Defined Statistics Where Who What Value 19

20 The Data Electronic Data Storage Devices Defined Statistics Where Who What Value Legal 20

21 The Data Electronic Data Storage Devices Defined Statistics Where Who What Value Legal 21

22 Policy 22

23 Policy Importance 23

24 Policy Importance Education 24

25 Policy Importance Education Management 25

26 Policy Importance Education Management Policy Design 26

27 Policy Importance Education Management Policy Design Purpose Why? 27

28 Policy Importance Education Management Policy Design Purpose Scope Who? 28

29 Policy Importance Education Management Policy Design Purpose Scope Policy How? 29

30 Policy Importance Education Management Policy Design Purpose Scope Policy Training 30

31 The Hunt for Devices 31

32 The Hunt for Devices Devices are Cheap and Easy to Find 32

33 The Hunt for Devices Devices are Cheap and Easy to Find Where to Find Devices Garage Sales 33

34 The Hunt for Devices Devices are Cheap and Easy to Find Where to Find Devices Thrift Shops Second Hand Goodwill 34

35 The Hunt for Devices Devices are Cheap and Easy to Find Where to Find Devices ebay 35

36 The Hunt for Devices Devices are Cheap and Easy to Find Where to Find Devices Craigslist 36

37 The Hunt for Devices Devices are Cheap and Easy to Find Where to Find Devices Recycle Centers Recycle Drives 37

38 The Hunt for Devices Devices are Cheap and Easy to Find Where to Find Devices Dumpster Diving 38

39 The Hunt for Devices Devices are Cheap and Easy to Find Where to Find Devices 39

40 The Hunt for Devices Devices are Cheap and Easy to Find Where to Find Devices Does it Even Matter? 40

41 Device Analysis & Data Recovery 41

42 Device Analysis & Data Recovery Organization 42

43 Device Analysis & Data Recovery Organization Where 43

44 Device Analysis & Data Recovery Organization Where Tools 44

45 Device Analysis & Data Recovery Organization Where Tools Software 45

46 Proper Disposal Methods 46

47 Proper Disposal Methods Format 47

48 Proper Disposal Methods Format DoD M 48

49 Proper Disposal Methods Format DoD M NIST Pub

50 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss Destroy 50

51 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe 51

52 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss 52

53 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss 53

54 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss Destroy 54

55 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss Destroy 55

56 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss Destroy 56

57 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss Destroy 57

58 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss Destroy 58

59 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss Destroy 59

60 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss Destroy 60

61 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss Destroy 61

62 Proper Disposal Methods Format DoD M NIST Pub Sanitization Wipe Degauss Destroy 62

63 Apply 63

64 How to Apply What You Have Learned Today In the first three months following this presentation you should: Identify Current Policy and Procedures Identify Devices (Threats) 64

65 How to Apply What You Have Learned Today In the first three months following this presentation you should: Identify Current Policy and Procedures Identify Devices (Threats) Within six months you should: Identify Workflow Create or Update Policy and Procedures Educate Staff 65

66 Conclusion 66

67 Conclusion Devices may contain data 67

68 Conclusion Devices may contain data Devices are cheap and easy to find 68

69 Conclusion Devices may contain data Devices are cheap and easy to find Device owners don t understand the risk 69

70 Conclusion Devices may contain data Devices are cheap and easy to find Device owners don t understand the risk Tools are easy to find and use 70

71 Conclusion Devices may contain data Devices are cheap and easy to find Device owners don t understand the risk Tools are easy to find and use Tools can be used to sanitize 71

72 Conclusion Devices may contain data Devices are cheap and easy to find Device owners don t understand the risk Tools are easy to find and use Tools can be used to sanitize Physical destruction is better (more fun) 72

73 Thank You John Michael Wright Mike (work) (not work) (Links & References) March 2, 2012 DAS

74 References Bar-Yosef, N. (2011). The commodities of underground markets. Retrieved on April 19, 2011 from California v. Greenwood. (1988). 486 U.S. 35 California v. Greenwood et.al. Certiorari to the Court of Appeal of California, Fourth Appellate District, No Retrieved on April 15 from CCC. (n.d.). California civil code section Retrieved on April 19, 2011 from CCISDA. (2011). Program best practices. Retrieved on June 3, 2011 from CMRR. (2011). Secure erase. Retrieve on April 19, 2011 from Desai, A. (2011). Commercial hacking: The mafia returns. Retrieved on April 19, 2011 fromhttp:// Mafia-Returns/

75 References Continued DoD M. (2006). National industry security program, operating manual. Retrieved on April 19, 2011 from Messmer, E. (2010). Data breach costs top $200 per customer record. Retrieved on June 7, 2011 from Mitnick, K. D. (2003). The art of deception controlling the human element of security. Hoboken, NJ: John Wiley & Sons Inc. NIST Pub (2006). NIST special publication , guidelines for media sanitation. Retrieved on April 19, 2011 from Perna, G. (2011). Black market prices: The low cost of stolen credit cards. Retrieved on April 19, 2011 from Wei, M., Grupp, L. M., Spada, F. E., & Swanson, S. (2011). Reliably erasing data from flash-based solid state drives. Retrieved on April 19, 2011 from 75

76 Tools Access Data: FTK Imager 2.5.3: Darik s Boot and Nuke: DiskInternals Uneraser: Disk Wipe: Helix 2009 R1: Identity Finder: Kon-Boot: NirSoft: Recuva: Secure Erase: Trinity Rescue Kit (TRK): WinTaylor: 76

SJSU Electronic Data Disposition Standard

SJSU Electronic Data Disposition Standard SJSU Electronic Data Disposition Standard Page 1 Executive Summary University data is at risk as long as it is persistently stored on electronic media. This means that data must be properly cared for during

More information

Challenges and Solutions for Effective SSD Data Erasure

Challenges and Solutions for Effective SSD Data Erasure Challenges and Solutions for Effective SSD Data Erasure Blancco White Paper Published 8 October 2013 First Edition Table of contents Introduction...3 The Simplicity And Complexity Of SSDs...4 Traditional

More information

Information Technology Services Guidelines

Information Technology Services Guidelines Page 1 of 10 Table of Contents 1 Purpose... 2 2 Entities Affected by These Guidelines... 2 3 Definitions... 3 4 Guidelines... 5 4.1 Electronic Sanitization and Destruction... 5 4.2 When is Sanitization

More information

UMBC POLICY ON ELECTRONIC MEDIA DISPOSAL UMBC# X-1.00.05

UMBC POLICY ON ELECTRONIC MEDIA DISPOSAL UMBC# X-1.00.05 UMBC POLICY ON ELECTRONIC MEDIA DISPOSAL UMBC# X-1.00.05 I. POLICY STATEMENT Increasing amounts of electronic data are being transmitted and stored on computer systems and electronic media by virtually

More information

That s why outsourcing using a Qualified Contractor is the best solution to the problem of assuring a compliant hard drive destruction audit trail.

That s why outsourcing using a Qualified Contractor is the best solution to the problem of assuring a compliant hard drive destruction audit trail. Why Zak Enterprises? Information contained on the hard drives of retired computers must be destroyed properly. Failure to do so can result in criminal penalties including fines and prison terms up to 20

More information

Solid-State Drives with Self-Encryption: Solidly Secure

Solid-State Drives with Self-Encryption: Solidly Secure Solid-State Drives with Self-Encryption: Solidly Secure 09/22/2011 Michael Willett Storage Security Strategist SAMSUNG SOLID STATE DRIVES Solid-State Drives SSD ADVANTAGES SOLID STATE DRIVES Save $$ on

More information

Security for Disk Drive Data at Rest Disk Drive Opportunities?

Security for Disk Drive Data at Rest Disk Drive Opportunities? Security for Disk Drive Data at Rest Disk Drive Opportunities?, CMRR gfhughes@ucsd.edu, 858-534-5317 Protect data where it lies In the disk drives where it resides Why not evolve the ATA password system

More information

How To Destroy Data From A Hard Drive

How To Destroy Data From A Hard Drive Safe, Secure and Certified Data Destruction Solutions to meet your individual needs Whether you require data destruction supplementary or exclusively to our IT disposal solution, our fully security screened

More information

State of Vermont. Digital Media and Hardware Disposal Standard. Date: Approved by: Policy Number:

State of Vermont. Digital Media and Hardware Disposal Standard. Date: Approved by: Policy Number: State of Vermont Digital Media and Hardware Disposal Standard Date: Approved by: Policy Number: 1.0 INTRODUCTION... 3 1.1 Authority... 3 1.2 Scope and Purpose:... 3 2.0 STANDARD... 3 2.1 Preface... 3 2.2

More information

Form #57, Revision #4 Date 7/15/2015 Data Destruction and Sanitation Program. Mobile (ON-SITE) Data Destruction/Shredding Services

Form #57, Revision #4 Date 7/15/2015 Data Destruction and Sanitation Program. Mobile (ON-SITE) Data Destruction/Shredding Services Data Destruction and Sanitation Program Mobile (ON-SITE) Data Destruction/Shredding Services 1 Diversified Recycling utilizes state of the art equipment for their data destruction and eradication services.

More information

Internet Security. For Home Users

Internet Security. For Home Users Internet Security For Home Users Basic Attacks Malware Social Engineering Password Guessing Physical Theft Improper Disposal Malware Malicious software Computer programs designed to break into and create

More information

CITY UNIVERSITY OF HONG KONG. Information Classification and

CITY UNIVERSITY OF HONG KONG. Information Classification and CITY UNIVERSITY OF HONG KONG Handling Standard (Approved by the Information Strategy and Governance Committee in December 2013) PUBLIC Date of Issue: 2013-12-24 Document Control Document Owner Classification

More information

Destruction and Disposal of Sensitive Data

Destruction and Disposal of Sensitive Data Destruction and Disposal of Sensitive Data Good Practice Guidelines Version: 3.0 Date: March 2015 1 Copyright 2015, Health and Social Care Information Centre. Contents 1. Introduction 3 1.2 Aims and Objectives

More information

Property Accounting Procedure Manual

Property Accounting Procedure Manual Property Accounting Procedure Manual Property Accounting Procedure 06-2013 1 Table of Contents Property Accounting Responsibilities... 3 General Guidelines Concerning Capital Equipment... 3 Acquisition...

More information

Data Recovery - What is possible to recover and how? Data Erasure - How to erase information in a secure way. Åke Ljungqvist, Country Manager Sweden

Data Recovery - What is possible to recover and how? Data Erasure - How to erase information in a secure way. Åke Ljungqvist, Country Manager Sweden Data Recovery - What is possible to recover and how? Data Erasure - How to erase information in a secure way Åke Ljungqvist, Country Manager Sweden Who is Ibas? Norway... Recovery of hard drives after

More information

"This is a truly remarkable attack, but not. just in its scope hackers successfully. penetrated one of the most secure

This is a truly remarkable attack, but not. just in its scope hackers successfully. penetrated one of the most secure ICPAK ANNUAL FORENSIC AUDIT CONFERENCE Digital Forensics in Fraud & Corruption Investigations 9 October 2014 Leisure Lodge Hotel, Diani Kenya Faith Basiye, CFE Head Group Forensic Services KCB Banking

More information

Ten Questions Your Board Should be asking about Cyber Security. Eric M. Wright, Shareholder

Ten Questions Your Board Should be asking about Cyber Security. Eric M. Wright, Shareholder Ten Questions Your Board Should be asking about Cyber Security Eric M. Wright, Shareholder Eric Wright, CPA, CITP Started my career with Schneider Downs in 1983. Responsible for all IT audit and system

More information

User Authentication Job Tracking Fax Transmission via RightFax Server Secure Printing Functions HDD/Memory Security Fax to Ethernet Connection Data

User Authentication Job Tracking Fax Transmission via RightFax Server Secure Printing Functions HDD/Memory Security Fax to Ethernet Connection Data User Authentication Job Tracking Fax Transmission via RightFax Server Secure Printing Functions HDD/Memory Security Fax to Ethernet Connection Data Security Kit Outline How do you protect your critical

More information

Presented by Evan Sylvester, CISSP

Presented by Evan Sylvester, CISSP Presented by Evan Sylvester, CISSP Who Am I? Evan Sylvester FAST Information Security Officer MBA, Texas State University BBA in Management Information Systems at the University of Texas Certified Information

More information

RRB-20: Health Insurance and Supplementary Medical Insurance Enrollment and Premium Payment System (MEDICARE)... 79 FR 58886. Name.

RRB-20: Health Insurance and Supplementary Medical Insurance Enrollment and Premium Payment System (MEDICARE)... 79 FR 58886. Name. Federal Register Effective Date System Location Security Classification Categories of Individuals Covered by the System Categories of Records in the System Authority for Maintenance of the System Purpose(s)

More information

State of South Carolina Policy Guidance and Training

State of South Carolina Policy Guidance and Training State of South Carolina Policy Guidance and Training Policy Workshop All Agency Mobile Security July 2014 Agenda Questions & Follow-Up Policy Workshop Overview & Timeline Policy Overview: Mobile Security

More information

Office Equipment Disposal Policy

Office Equipment Disposal Policy Office Equipment Disposal Policy R ISK MANAGEMENT HANDOUTS OF L AWYERS MUTUAL LAWYERS MUTUAL LIABILITY INSURANCE COMPANY OF NORTH CAROLINA 5020 Weston Parkway, Suite 200, Cary, North Carolina 27513 Post

More information

This policy shall be reviewed at least annually and updated as needed to reflect changes to business objectives or the risk environment.

This policy shall be reviewed at least annually and updated as needed to reflect changes to business objectives or the risk environment. - 1. Policy Statement All card processing activities and related technologies must comply with the Payment Card Industry Data Security Standard (PCI-DSS) in its entirety. Card processing activities must

More information

Protecting Data in Decommissioned IT Assets: Factors, Tools and Methods

Protecting Data in Decommissioned IT Assets: Factors, Tools and Methods SECURIS SM Protecting Data in Decommissioned IT Assets: Factors, Tools and Methods Information Systems Security Association (ISSA) Baltimore Chapter Monthly Meeting January 27, 2016 Hugh McLaurin, CSDS

More information

Tutorial on Disk Drive Data Sanitization. Summary. Introduction. Table of Contents

Tutorial on Disk Drive Data Sanitization. Summary. Introduction. Table of Contents Tutorial on Disk Drive Data Sanitization Gordon Hughes, UCSD CMRR (gfhughes@ucsd.edu) Tom Coughlin, Coughlin Associates (tom@tomcoughlin.com) Summary Summary: user data is left on disk drives removed from

More information

Deciphering the Safe Harbor on Breach Notification: The Data Encryption Story

Deciphering the Safe Harbor on Breach Notification: The Data Encryption Story Deciphering the Safe Harbor on Breach Notification: The Data Encryption Story Healthcare organizations planning to protect themselves from breach notification should implement data encryption in their

More information

CANADIAN PAYMENTS ASSOCIATION ASSOCIATION CANADIENNE DES PAIEMENTS STANDARD 012 IMAGE SECURITY STANDARD

CANADIAN PAYMENTS ASSOCIATION ASSOCIATION CANADIENNE DES PAIEMENTS STANDARD 012 IMAGE SECURITY STANDARD CANADIAN PAYMENTS ASSOCIATION ASSOCIATION CANADIENNE DES PAIEMENTS STANDARD 012 IMAGE SECURITY STANDARD 2013 CANADIAN PAYMENTS ASSOCIATION 2013 ASSOCIATION CANADIENNE DES PAIEMENTS This Rule is copyrighted

More information

Media Disposition and Sanitation Procedure

Media Disposition and Sanitation Procedure Media Disposition and Sanitation Procedure Revision History Version Date Editor Nature of Change 1.0 11/14/06 Kelly Matt Initial Release Table of Contents 1.0 Overview... 1 2.0 Purpose... 1 3.0 Scope...

More information

Firmware security features in HP Compaq business notebooks

Firmware security features in HP Compaq business notebooks HP ProtectTools Firmware security features in HP Compaq business notebooks Embedded security overview... 2 Basics of protection... 2 Protecting against unauthorized access user authentication... 3 Pre-boot

More information

Understanding Data Destruction and How to Properly Protect Your Business

Understanding Data Destruction and How to Properly Protect Your Business Understanding Data Destruction and How to Properly Protect Your Business Understanding Data Destruction and How to Properly Protect Your Business I. Abstract This document is designed to provide a practical

More information

Privacy Data Loss. Privacy Data Loss. Identity Theft. The Legal Issues

Privacy Data Loss. Privacy Data Loss. Identity Theft. The Legal Issues Doing Business in Oregon Under the Oregon Consumer Identity Theft Protection Act and Related Privacy Risks Privacy Data Loss www.breachblog.com Presented by: Mike Porter March 10, 2009 2 Privacy Data Loss

More information

Data Security Using TCG Self-Encrypting Drive Technology

Data Security Using TCG Self-Encrypting Drive Technology Data Security Using TCG Self-Encrypting Drive Technology June 11, 2013 2:00PM EDT Copyright 2013 Trusted Computing Group 1 Copyright 2013 Trusted Computing Group 2 Tom Coughlin, Founder, Coughlin Associates.

More information

"This is a truly remarkable attack, but not. just in its scope hackers successfully. penetrated one of the most secure

This is a truly remarkable attack, but not. just in its scope hackers successfully. penetrated one of the most secure ICPAK ANNUAL FORENSIC AUDIT CONFERENCE Digital Forensics in Fraud & Corruption Investigations 9 October 2014 Leisure Lodge Hotel, Diani Kenya Faith Basiye, CFE Head Group Forensic Services KCB Banking

More information

Other terms are defined in the Providence Privacy and Security Glossary

Other terms are defined in the Providence Privacy and Security Glossary Subject: Device and Media Controls Department: Enterprise Security Executive Sponsor: EVP/COO Approved by: Rod Hochman, MD - President/CEO Policy Number: New Date: Revised 10/11/2013 Reviewed Policy Owner:

More information

Critical Data Guide. A guide to handling critical information at Indiana University

Critical Data Guide. A guide to handling critical information at Indiana University Critical Data Guide A guide to handling critical information at Indiana University What is critical information? IU defines critical information as sensitive data requiring the highest level of protection.

More information

John Essner, CISO Office of Information Technology State of New Jersey

John Essner, CISO Office of Information Technology State of New Jersey John Essner, CISO Office of Information Technology State of New Jersey http://csrc.nist.gov/publications/nistpubs/800-144/sp800-144.pdf Governance Compliance Trust Architecture Identity and Access Management

More information

CPR: Circumstances, Prevention and Response in Safeguarding Personal Healthcare Information

CPR: Circumstances, Prevention and Response in Safeguarding Personal Healthcare Information September 14, 2010 CPR: Circumstances, Prevention and Response in Safeguarding Personal Healthcare Information 2010 Kroll Ontrack Inc. www.ontrackdatarecovery.com Agenda Introduction 1 Agenda Introduction

More information

The Importance of Data Retention

The Importance of Data Retention Section 2 Information Systems Security & Web Technologies and Security Abstract Information Security Leakage: A Forensic Analysis of USB Storage Disks A.Adam and N.L.Clarke Centre for Information Security

More information

User Authentication Job Tracking Fax Transmission via RightFax Server Secure Printing Functions HDD/Memory Security Fax to Ethernet Connection

User Authentication Job Tracking Fax Transmission via RightFax Server Secure Printing Functions HDD/Memory Security Fax to Ethernet Connection User Authentication Job Tracking Fax Transmission via RightFax Server Secure Printing Functions HDD/Memory Security Fax to Ethernet Connection Outline How do you protect your critical confidential data?

More information

A Study of Hard Drive Forensics on Consumers PCs: Data Recovery and Exploitation

A Study of Hard Drive Forensics on Consumers PCs: Data Recovery and Exploitation A Study of Hard Drive Forensics on Consumers PCs: Data Recovery and Exploitation B. Dawn Medlin Appalachian State University Joseph A. Cazier Appalachian State University One of the first actions to take

More information

Data Recovery - What is possible to recover and how?

Data Recovery - What is possible to recover and how? Data Recovery - What is possible to recover and how? Data Erasure - How to erase information in a secure way Åke Ljungqvist, Country Manager Sweden Who is Ibas? Norway... Recovery of hard drives after

More information

RMAR Technologies Pvt. Ltd.

RMAR Technologies Pvt. Ltd. Course Name : StartXHack V2.0 Ethical Hacking & Cyber Security Course Duration : 2 Days (8Hrs./day) Course Fee : INR 1000/participant Course Module : 1. Introduction to Ethical Hacking a. What is Ethical

More information

Managing and Automating Data Erasure for Mobile Devices: STRATEGIES FOR RECYCLERS AND IT ASSET DISPOSAL SPECIALISTS

Managing and Automating Data Erasure for Mobile Devices: STRATEGIES FOR RECYCLERS AND IT ASSET DISPOSAL SPECIALISTS Managing and Automating Data Erasure for Mobile Devices: STRATEGIES FOR RECYCLERS AND IT ASSET DISPOSAL SPECIALISTS Blancco White Paper Published 14 February 2013 Introduction Advanced mobile devices like

More information

DATA SECURITY POLICY. Data Security Policy

DATA SECURITY POLICY. Data Security Policy Data Security Policy Contents 1. Introduction 3 2. Purpose 4 3. Data Protection 4 4. Customer Authentication 4 5. Physical Security 5 6. Access Control 6 7. Network Security 6 8. Software Security 7 9.

More information

Technical Reference Document Summary of NIST Special Publication 800-88: Guidelines for Media Sanitization

Technical Reference Document Summary of NIST Special Publication 800-88: Guidelines for Media Sanitization TECHNICAL REFERENCE DOCUMENT Technical Reference Document Summary of NIST Special Publication 800-88: Guidelines for Media Sanitization Recommendations Key Points: of the National Real world compliance

More information

SOASTA CloudTest Performance Data Retention and Security Policy. Whitepaper

SOASTA CloudTest Performance Data Retention and Security Policy. Whitepaper SOASTA CloudTest Performance Data Retention and Security Policy Whitepaper Table of Contents Executive Summary: Data Security... 3 1. SOASTA s Data Retention Policy... 3 1.1 Test Development... 3 1. 2

More information

Cybersecurity Workshop

Cybersecurity Workshop Cybersecurity Workshop February 10, 2015 E. Andrew Keeney, Esq. Kaufman & Canoles, P.C. E. Andrew Keeney, Esq. Kaufman & Canoles, P.C. 150 West Main Street, Suite 2100 Norfolk, VA 23510 (757) 624-3153

More information

Why do we need to protect our information? What happens if we don t?

Why do we need to protect our information? What happens if we don t? Warwickshire County Council Why do we need to protect our information? What happens if we don t? Who should read this? What does it cover? Linked articles All WCC employees especially mobile and home workers

More information

Technical Proposal on ATA Secure Erase Gordon Hughes+ and Tom Coughlin* +CMRR, University of California San Diego *Coughlin Associates

Technical Proposal on ATA Secure Erase Gordon Hughes+ and Tom Coughlin* +CMRR, University of California San Diego *Coughlin Associates Technical Proposal on ATA Secure Erase Gordon Hughes+ and Tom Coughlin* +CMRR, University of California San Diego *Coughlin Associates Introduction and Summary Secure erase SE is defined in the ATA specification

More information

Sierra College ADMINISTRATIVE PROCEDURE No. AP 3721

Sierra College ADMINISTRATIVE PROCEDURE No. AP 3721 Sierra College ADMINISTRATIVE PROCEDURE No. AP 3721 Electronic Information Security and Data Backup Procedures Date Adopted: 4/13/2012 Date Revised: Date Reviewed: References: Health Insurance Portability

More information

Solid State Drives (SSD) with Self Encryption: Solidly Secure Michael Willett Storage Security Strategist Independent Consultant

Solid State Drives (SSD) with Self Encryption: Solidly Secure Michael Willett Storage Security Strategist Independent Consultant Solid State Drives (SSD) with Self Encryption: Solidly Secure Michael Willett Storage Security Strategist Independent Consultant Flash Memory Summit 2014 Santa Clara, CA 1 The Problem 2005-2013: over 864,108,052

More information

Resolving Security Issues when working with R&S UPV, R&S UPV66, R&S UPP200, R&S UPP400, R&S UPP800 in Secure Areas

Resolving Security Issues when working with R&S UPV, R&S UPV66, R&S UPP200, R&S UPP400, R&S UPP800 in Secure Areas Products: Audio Analyzers R&S UPV, R&S UPV66, R&S UPP200, R&S UPP400, R&S UPP800 Resolving Security Issues when working with R&S UPV, R&S UPV66, R&S UPP200, R&S UPP400, R&S UPP800 in Secure Areas Based

More information

Dublin City University

Dublin City University Asset Management Policy Asset Management Policy Contents Purpose... 1 Scope... 1 Physical Assets... 1 Software Assets... 1 Information Assets... 1 Policies and management... 2 Asset Life Cycle... 2 Asset

More information

Closing the Back Door: Managing IT Data Security During Equipment Disposal

Closing the Back Door: Managing IT Data Security During Equipment Disposal Closing the Back Door: Managing IT Data Security During Equipment Disposal By: Kevin Myrant and Neil Peters-Michaud April 28, 2005 Executive Summary Companies invest significantly in securing data in their

More information

Cyber Self Assessment

Cyber Self Assessment Cyber Self Assessment According to Protecting Personal Information A Guide for Business 1 a sound data security plan is built on five key principles: 1. Take stock. Know what personal information you have

More information

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 What is HIPAA? Health Insurance Portability & Accountability Act of 1996 Effective April 13, 2003 Federal Law HIPAA Purpose:

More information

Data Security & Information Sharing

Data Security & Information Sharing Data Security & Information Sharing A review of the requirements and necessary steps to secure access to DOH provided Medicaid PHI data, and the impact of opt-out on information sharing outside of the

More information

introducing COMPUTER ANTI FORENSIC TECHNIQUES

introducing COMPUTER ANTI FORENSIC TECHNIQUES introducing COMPUTER ANTI FORENSIC TECHNIQUES COMPUTER FORENSIC DATA RECOVERY TECHNIQUES AND SOLUTIONS WORKSHOP Executive Summary Computer Forensics, a term that precisely identifies the discipline that

More information

Magnetic Data Recovery The Hidden Threat. Joshua J Sawyer. East Carolina University

Magnetic Data Recovery The Hidden Threat. Joshua J Sawyer. East Carolina University 1 Running head: MAGNETIC DATA RECOVERY THE HIDDEN THREAT Magnetic Data Recovery The Hidden Threat Joshua J Sawyer East Carolina University 2 Abstract In presenting the dangers of magnetic data recovery,

More information

Data Privacy & Security: Essential Questions Every Business Must Ask

Data Privacy & Security: Essential Questions Every Business Must Ask Data Privacy & Security: Essential Questions Every Business Must Ask Presented by: Riddell Williams P.S. Riddell Williams P.S. May 6, 2015 #4841-4703-9779 Innocent? 2 Overview 3 basic questions every business

More information

THE CYBERSECURITY SKILL GAP: WHAT EMPLOYERS WANT YOU TO KNOW

THE CYBERSECURITY SKILL GAP: WHAT EMPLOYERS WANT YOU TO KNOW www.isaca.org/cyber THE CYBERSECURITY SKILL GAP: WHAT EMPLOYERS WANT YOU TO KNOW ROBERT E STROUD CGEIT CRISC INTERNATIONAL PRESIDENT ISACA & VP STRATEGY & INNOVATION CA TECHNOLOGIES February 2015 ISACA

More information

Kentucky Information Technology Standards (KITS)

Kentucky Information Technology Standards (KITS) Kentucky Information Technology Standards (KITS) Full KITS Report - Word Search EAS EAS Name Standard KITS 5010 Intrusion Detection and Prevention Products must support approved Enterprise standards in

More information

Identity Theft and Medical Theft. *Christine Stagnetto-Sarmiento, Oglala Lakota College, USA

Identity Theft and Medical Theft. *Christine Stagnetto-Sarmiento, Oglala Lakota College, USA 1 Identity Theft and Medical Theft *Christine Stagnetto-Sarmiento, Oglala Lakota College, USA *Corresponding Author, 490 Piya Wiconi Road, Kyle-South Dakota (605) 455-6110 csarmiento@olc.edu Introduction

More information

IT asset disposal for organisations

IT asset disposal for organisations ICO lo Data Protection Act Contents Introduction... 1 Overview... 2 What the DPA says... 3 Create an asset disposal strategy... 3 How will devices be disposed of when no longer needed?... 3 Conduct a risk

More information

BACKUP AND CONTIGENCY PLANS (DISASTER RECOVERY)

BACKUP AND CONTIGENCY PLANS (DISASTER RECOVERY) BACKUP AND CONTIGENCY PLANS (DISASTER RECOVERY) PURPOSE The purpose of this policy is to describe the backup and contingency plans, including disaster recovery planning, that will be implemented to ensure

More information

Hands-On How-To Computer Forensics Training

Hands-On How-To Computer Forensics Training j8fm6pmlnqq3ghdgoucsm/ach5zvkzett7guroaqtgzbz8+t+8d2w538ke3c7t 02jjdklhaMFCQHihQAECwMCAQIZAQAKCRDafWsAOnHzRmAeAJ9yABw8v2fGxaq skeu29sdxrpb25zidxpbmznogtheories...ofhilz9e1xthvqxbb0gknrc1ng OKLbRXF/j5jJQPxXaNUu/It1TQHSiyEumrHNsnn65aUMPnrbVOVJ8hV8NQvsUE

More information

Stopping Leaks: How to Confront the Challenges of Endpoint Information Security from HDD. Whitepaper

Stopping Leaks: How to Confront the Challenges of Endpoint Information Security from HDD. Whitepaper Stopping Leaks: How to Confront the Challenges of Endpoint Information Security from HDD intimus consulting is a division of the MARTIN YALE GROUP Bergheimer Strasse 6-12 88677 Markdorf / Germany www.intimusconsulting.com

More information

ACRONYMS: HIPAA: Health Insurance Portability and Accountability Act PHI: Protected Health Information

ACRONYMS: HIPAA: Health Insurance Portability and Accountability Act PHI: Protected Health Information NAMI EASTSIDE - 13 POLICY: Privacy and Security of Protected Health Information (HIPAA Policies and Procedures) DATE APPROVED: Pending INTENT: (At present, none of the activities that NAMI Eastside provides

More information

DATA BREACH LAW UPDATE Global Trends Legal Complexities

DATA BREACH LAW UPDATE Global Trends Legal Complexities DATA BREACH LAW UPDATE Global Trends Legal Complexities Moderator: Lucy L. Thomson Livingston PLLC Panelists: Thomas Smedinghoff Edwards Wildman Eric Hibbard Hitachi Data Systems Robert Thibadeau Wave

More information

NATIONAL SECURITY AGENCY CENTRAL SECURITY SERVICE NSA/CSS POLICY MANUAL 9-12. Issue Date: 15 December 2014 Revised:

NATIONAL SECURITY AGENCY CENTRAL SECURITY SERVICE NSA/CSS POLICY MANUAL 9-12. Issue Date: 15 December 2014 Revised: NATIONAL SECURITY AGENCY CENTRAL SECURITY SERVICE NSA/CSS POLICY MANUAL 9-12 Issue Date: 15 December 2014 Revised: NSA/CSS STORAGE DEVICE SANITIZATION MANUAL PURPOSE AND SCOPE This manual provides guidance

More information

Computer Forensics. Computer Forensics: History, Tools and Outlooks. By John Burns IT-103-002. Research Paper

Computer Forensics. Computer Forensics: History, Tools and Outlooks. By John Burns IT-103-002. Research Paper 1 Computer Forensics: History, Tools and Outlooks By John Burns IT-103-002 Research Paper 02/25/2012 "By placing this statement on my webpage, I certify that I have read and understand the GMU Honor Code

More information

Enforcement of Health Information Privacy & Security Standards Federal Enforcement Through Recent Cases and Tools to Measure Regulatory Compliance

Enforcement of Health Information Privacy & Security Standards Federal Enforcement Through Recent Cases and Tools to Measure Regulatory Compliance Enforcement of Health Information Privacy & Security Standards Federal Enforcement Through Recent Cases and Tools to Measure Regulatory Compliance Iliana Peters, JD, LLM, HHS Office for Civil Rights Kevin

More information

Awareness, Deterrence and

Awareness, Deterrence and Identity Theft Awareness, Deterrence and Recovery Ian Howe Assistant Attorney General Consumer Protection Division Opinions presented are those of the speaker and not an official opinion of the Office

More information

Data Breach Response Planning: Laying the Right Foundation

Data Breach Response Planning: Laying the Right Foundation Data Breach Response Planning: Laying the Right Foundation September 16, 2015 Presented by Paige M. Boshell and Amy S. Leopard babc.com ALABAMA I DISTRICT OF COLUMBIA I FLORIDA I MISSISSIPPI I NORTH CAROLINA

More information

Information Protection in Today s Changing Mobile and Cloud Environments

Information Protection in Today s Changing Mobile and Cloud Environments Information Protection in Today s Changing Mobile and Cloud Environments Art Gilliland, Sr. Vice President Symantec, Information Security Group Session ID: SPO1-107 Session Classification: Intermediate

More information

Guidance Specifying Technologies and Methodologies DEPARTMENT OF HEALTH AND HUMAN SERVICES

Guidance Specifying Technologies and Methodologies DEPARTMENT OF HEALTH AND HUMAN SERVICES DEPARTMENT OF HEALTH AND HUMAN SERVICES 45 CFR PARTS 160 and 164 Guidance Specifying the Technologies and Methodologies That Render Protected Health Information Unusable, Unreadable, or Indecipherable

More information

IT Auditing and. Discussion Topics. What is IT Auditing?

IT Auditing and. Discussion Topics. What is IT Auditing? IT Auditing and Computer Forensics Kevin H. Doar, CISA Auditor Discussion Topics What is IT Auditing? IT Auditor Skillset IT Auditing Standards & Frameworks IT Controls with Case Examples The Direction

More information

plantemoran.com What School Personnel Administrators Need to know

plantemoran.com What School Personnel Administrators Need to know plantemoran.com Data Security and Privacy What School Personnel Administrators Need to know Tomorrow s Headline Let s hope not District posts confidential data online (Tech News, May 18, 2007) In one of

More information

ACCOUNTABLE HEALTHCARE IPA HIPAA PRIVACY AND SECURITY TRAINING. By: Jerry Jackson Compliance and Privacy Officer

ACCOUNTABLE HEALTHCARE IPA HIPAA PRIVACY AND SECURITY TRAINING. By: Jerry Jackson Compliance and Privacy Officer ACCOUNTABLE HEALTHCARE IPA HIPAA PRIVACY AND SECURITY TRAINING By: Jerry Jackson Compliance and Privacy Officer 1 1 Introduction Welcome to Privacy and Security Training course. This course will help you

More information

Managing Data Erasure in the Enterprise: Automated Processes for Optimal Efficiency

Managing Data Erasure in the Enterprise: Automated Processes for Optimal Efficiency Managing Data Erasure in the Enterprise: Automated Processes for Optimal Efficiency Blancco White Paper Published 30 June 2014 Table of contents Introduction...2 Threats from improperly disposed IT equipment...4

More information

PGP Whole Disk Encryption Training

PGP Whole Disk Encryption Training PGP Whole Disk Encryption Training Agenda WDE Overview Licensing Universal Server & Client Basics Installation Password Recovery OS Maintenance Support Questions 2 Whole Disk Encryption Protects against:

More information

SOUTHWEST VIRGINIA COMMUNITY COLLEGE RECORDS MANAGEMENT POLICY

SOUTHWEST VIRGINIA COMMUNITY COLLEGE RECORDS MANAGEMENT POLICY SOUTHWEST VIRGINIA COMMUNITY COLLEGE RECORDS MANAGEMENT POLICY Statement of Intent This policy establishes the general responsibilities for management, retention, and disposition of SOUTHWEST VIRGINIA

More information

Secure Data Disposal. By Joe Stuart ACC 626

Secure Data Disposal. By Joe Stuart ACC 626 By Joe Stuart ACC 626 Introduction With each passing year, businesses, and the public in general, are becoming more dependent upon electronic storage methods due to the greater efficiency with which data

More information

Preventing Final Disposition Data Breaches

Preventing Final Disposition Data Breaches Preventing Final Disposition Data Breaches How to Evaluate an ITAD Vendor for Your Organization By: Jim Kegley Founder, President and CEO, U.S. Micro Corporation The IT asset disposition (ITAD) industry

More information

الدكتور عادل إسماعيل العلوي الجامعة الملكية للبنات البحرين نائب رئيس الجمعية الدولية لضبط ومراقبة نظم المعلومات

الدكتور عادل إسماعيل العلوي الجامعة الملكية للبنات البحرين نائب رئيس الجمعية الدولية لضبط ومراقبة نظم المعلومات - البحرين الدكتور عادل إسماعيل العلوي الجامعة الملكية للبنات البحرين نائب رئيس الجمعية الدولية لضبط ومراقبة نظم المعلومات Agenda The problem Traditional Methods Case Study Recommendation The problem What

More information

CYBERSECURITY: THREATS, SOLUTIONS AND PROTECTION. Robert N. Young, Director Carruthers & Roth, P.A. Email: rny@crlaw.com Phone: (336) 478-1131

CYBERSECURITY: THREATS, SOLUTIONS AND PROTECTION. Robert N. Young, Director Carruthers & Roth, P.A. Email: rny@crlaw.com Phone: (336) 478-1131 CYBERSECURITY: THREATS, SOLUTIONS AND PROTECTION Robert N. Young, Director Carruthers & Roth, P.A. Email: rny@crlaw.com Phone: (336) 478-1131 TOPICS 1. Threats to your business s data 2. Legal obligations

More information

Using Technology Control Plans in Export Compliance. Mary Beran, Georgia Tech David Brady, Virginia Tech

Using Technology Control Plans in Export Compliance. Mary Beran, Georgia Tech David Brady, Virginia Tech Using Technology Control Plans in Export Compliance Mary Beran, Georgia Tech David Brady, Virginia Tech What is a Technology Control Plan (TCP)? The purpose of a TCP is to control the access and dissemination

More information

IN THE COURT OF APPEALS OF THE STATE OF IDAHO. Docket No. 41435 ) ) ) ) ) ) ) ) ) )

IN THE COURT OF APPEALS OF THE STATE OF IDAHO. Docket No. 41435 ) ) ) ) ) ) ) ) ) ) IN THE COURT OF APPEALS OF THE STATE OF IDAHO Docket No. 41435 STATE OF IDAHO, Plaintiff-Respondent, v. ANDREY SERGEYEVICH YERMOLA, Defendant-Appellant. 2015 Unpublished Opinion No. 348 Filed: February

More information

Computing Services Information Security Office. Security 101

Computing Services Information Security Office. Security 101 Computing Services Information Security Office Security 101 Definition of Information Security Information security is the protection of information and systems from unauthorized access, disclosure, modification,

More information

Virginia Commonwealth University School of Medicine Information Security Standard

Virginia Commonwealth University School of Medicine Information Security Standard Virginia Commonwealth University School of Medicine Information Security Standard Title: Scope: Data Handling and Storage Standard This standard is applicable to all VCU School of Medicine personnel. Approval

More information

by: Scott Baranowski Community Bank Auditors Group Best Practices in Auditing Record Retention, Safeguarding Paper Documents, GLBA and Privacy

by: Scott Baranowski Community Bank Auditors Group Best Practices in Auditing Record Retention, Safeguarding Paper Documents, GLBA and Privacy Community Bank Auditors Group Best Practices in Auditing Record Retention, Safeguarding Paper Documents, GLBA and Privacy June 10, 2015 MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT

More information

NO. STATE OF TEXAS, IN THE DISTRICT COURT OF Plaintiff, v. LIBERTY COUNTY, TEXAS. CVS PHARMACY, INC. Defendant. JUDICIAL DISTRICT

NO. STATE OF TEXAS, IN THE DISTRICT COURT OF Plaintiff, v. LIBERTY COUNTY, TEXAS. CVS PHARMACY, INC. Defendant. JUDICIAL DISTRICT NO. STATE OF TEXAS, IN THE DISTRICT COURT OF Plaintiff, v. LIBERTY COUNTY, TEXAS CVS PHARMACY, INC. Defendant. JUDICIAL DISTRICT PLAINTIFF S ORIGINAL PETITION AND APPLICATION FOR INJUNCTION TO THE HONORABLE

More information

Managing Information Security @ Stanford

Managing Information Security @ Stanford Managing Information Security @ Stanford March 4, 2011 Tina Darmohray, Assistant Vice President and Chief Information Security Officer 1 Stanford Information Assets Stanford s diversity results in many

More information

Getting a new computer or smartphone is always exciting but do you know what to do with your old one?

Getting a new computer or smartphone is always exciting but do you know what to do with your old one? TrendLabs Getting a new computer or smartphone is always exciting but do you know what to do with your old one? The truth is that it s not as simple as just giving them away or selling them. You have to

More information

Hard Drive Data Security. Chris Bilello Director, Business Development Konica Minolta Business Solutions U.S.A., Inc.

Hard Drive Data Security. Chris Bilello Director, Business Development Konica Minolta Business Solutions U.S.A., Inc. Hard Drive Data Security Chris Bilello Director, Business Development Konica Minolta Business Solutions U.S.A., Inc. Konica Minolta Security Features On April 19, CBS News aired a story that highlighted

More information

How To Understand The Bring Your Own Device To School Policy At A School

How To Understand The Bring Your Own Device To School Policy At A School The Thomas Hardye School Bring Your Own Device to School (BYOD) Policy for Students Adopted by Personnel & Resources Committee 1 st September 2014 Review date: 31 st August 2015 Signed by Chair:. CONTENTS

More information

Data Access Request Service

Data Access Request Service Data Access Request Service Guidance Notes on Security Version: 4.0 Date: 01/04/2015 1 Copyright 2014, Health and Social Care Information Centre. Introduction This security guidance is for organisations

More information

Secure Mobile Shredding and. Solutions

Secure Mobile Shredding and. Solutions Secure Mobile Shredding and Data Erasure Solutions SECURE MOBILE SHREDDING & DATA ERASURE SERVICES... NCE s mobile shredding and data erasure service permanently destroys your data in a secure and controlled

More information

Data Security Policy. 1. Document Status. Version 1.0. Approval. Review By June 2011. Secure Research Database Analyst. Change History. 1 Version 1.

Data Security Policy. 1. Document Status. Version 1.0. Approval. Review By June 2011. Secure Research Database Analyst. Change History. 1 Version 1. Data Security Policy 1. Document Status Security Classification Level 4 - PUBLIC Version 1.0 Status DRAFT Approval Life 3 Years Review By June 2011 Owner Secure Research Database Analyst Change History

More information