• No results found

USG Data at Rest Encryption/Protection

N/A
N/A
Protected

Academic year: 2021

Share "USG Data at Rest Encryption/Protection"

Copied!
11
0
0

Loading.... (view fulltext now)

Full text

(1)

USG Data at Rest

Encryption/Protection

Briefing for the Symantec Government g y

Symposium

Preventing Data Loss Panel Session Preventing Data Loss Panel Session

31 July 2008 31 July 2008

(2)

USG DAR/PII Encryption – Issues….

ƒ Policy awareness, compliance, and technology per OMB policy directive M-06-16 and DoD policy

memorandums on mobile computing devices and PII ƒ USG loss of laptops removable storage media

ƒ USG loss of laptops, removable storage media, sensitive data, and PII:

– Multiple government agency (Federal, State, Local) p g g y ( ) loss of laptops, PDAs, removable storage media

– DoD thumbdrives (Afghan bazaar)

B iti h t l f PII i i i id t

ƒ British government loss of PII via various incidents ƒ Numerous commercial PII incidents

(3)

Data at Rest Tiger Team (DARTT)

Background

g

ƒ Created by DoD CIO and DoD C4 Principals in Aug 06, joined by GSA/Civil Agencies in Dec 06, chartered PM via DoD CIO Acquisition Memo Mar 07

via DoD CIO Acquisition Memo Mar 07

ƒ Collaborative intergovernmental effort - 20 DoD

Components, 18 Federal agencies, State/Local, NATO ƒ Assessed shortfalls in USG DAR encryption policies,

practices, initiatives, and technology solutions;

focusing on mobile computing devices and PII data focusing on mobile computing devices and PII data ƒ Used an unprecedented, competitive, and rapid (Dec

06 - June 07) acquisition process (FAR Part 8) to

establish DoD ESI/GSA SmartBUY acquisition vehicles establish DoD ESI/GSA SmartBUY acquisition vehicles resulting in 11 BPAs (open to all USG agencies).

ƒ Innovative Tech Refresh/Upgrade process using GSA collaboration portal (https://collab.core.gov).

(4)

DARTT Status

ƒ 11 BPAs awarded in June 07 with discounts up to 98% off GSA Schedule pricing

ƒ Unprecedented leveraging of USG customer baseUnprecedented leveraging of USG customer base

ƒ Over 917,600 DAR encryption licenses sold to Federal, State, and Local govt agencies since award

ƒ Represents $18M in sales with $82M in verifiable costRepresents $18M in sales with $82M in verifiable cost avoidance; or put another way, the USG has

purchased $100M worth of DAR encryption products (at GSA Schedule pricing) for an actual cost of $18M (at GSA Schedule pricing) for an actual cost of $18M ƒ Comprehensive DARTT information available to .gov

and .mil accounts at GSA collaboration portal:

https://collab core gov https://collab.core.gov

ƒ More information:

http://www.defenselink.mil/releases/release.aspx?releaseid=11025 http://www.defenselink.mil/releases/release.aspx?releaseid=11684p p http://www.defenselink.mil/releases/release.aspx?releaseid=12041

(5)

DARTT – the Good News….

ƒ Synchronization of govt policy & technology acquisition ƒ Collaborative effort across Federal, State, Local

agencies and NATO agencies and NATO

ƒ Public awareness campaign – recent DoD/GSA joint press releases; CNSS Annual Report (Mar 08); and articles in FedTech, FCW, GCN, Military Information Technology, and Network World magazines

ƒ Highly successful Technical Refreshment/Upgrade ƒ Highly successful Technical Refreshment/Upgrade

process (https://collab.core.gov) – DARTT has approved 3 vendor BPA contract modification

l 1 i

proposals, 1 more in-process.

ƒ DARTT’s on-going Advisory initiative; written and

disseminated two DARTT Advisories for the ColdBoot disseminated two DARTT Advisories for the ColdBoot and FireWire vulnerabilities for USG/public awareness.

(6)

DARTT Awards

S l j d f th DARTT

ƒ Several major awards for the DARTT program:

– DoD Excellence in Information Assurance Award (Feb 2008)

(Feb 2008)

– 2008 Intergovernmental Government Solutions

Award at the 28th Annual Management of Change

C f (J 2008)

Conference (June 2008)

– Executive Alliance nomination for Mid-Atlantic Project of the Year Award (June 2008)

(7)

DARTT Contacts:

Single source for comprehensive DARTT information:

David Hollis

Program Manager/Co-Chair

g p

ƒ https://collab.core.gov (GSA collaboration web site, .gov/.mil only)

Vendor and BPA ordering information:

htt // / tb [email protected] 703-602-9982 Sharon Terango ƒ http://www.gsa.gov/smartbuy or http://www.esi.mil/main.asp.

BPA Points of Contact for Federal and State/Local Agencies

Sharon Terango Co-chair

[email protected]

703-306-6104

ƒ Sharon Terango - SmartBUY IA PM (703) 306-6104

[email protected]

ƒ Michael Hargrove - SmartBUY Contracting Officer (703) 306-7701 [email protected]

Robby Ann Carter Technical Director

[email protected]

306 7701 [email protected]

BPA Points of Contact for DoD, IC, DHS, and NATO:

ƒ Maurice Griffin - ESI IA Software Product Manager (334) 416-4229 [email protected]

y @

(8)

BACKUP SLIDES

BACKUP SLIDES

(9)

ACRONYMS

„ DAR – Data at Rest

„ DARTT – Data at Rest Tiger Team PII P ll Id tifi bl I f ti

„ PII – Personally Identifiable Information

„ ESI – DoD Enterprise Software Initiative

„ BPA Blanket Purchase Agreement

„ BPA – Blanket Purchase Agreement

„ RFQ – Request for Quote

„ FIPS – Federal Information Processing StandardsS ede a o a o ocess g S a da ds

„ FDE – Full Disk Encryption

„ FES – File/Folder Encryption System

„ RSM – Removable Storage Media

„ SME – Subject Matter Expert

(10)

Awardees

1 MTM Technologies / Mobile Armor Mobile Guardian FDE / FES Software 2 Rocky Mountain Ram Safeboot FDE / FES SW & HW 3 Carahsoft / Information Security Corp. Secret Agent FES Software

4 Spectrum Systems Safeboot FDE / FES Software

5 SafeNet ProtectDrive FDE Software

6 Hi Tech Service / Encryption Solutions SkyLOCK FES Software 7 Autonomic Resources / WinMagic &

Spyrus

WinMagic SecureDoc & Spyrus Talisman SD

FDE / FES HW &SW 8 GovBUYS / WinMagic SecureDoc FDE / FES Software 8 GovBUYS / WinMagic SecureDoc FDE / FES Software 9 Intelligent Decisions / Credant

Technologies

Mobile Guardian FES Software

10 Merlin Int’l / Guardian Edge e t / Gua d a dge Guardian Edge FDE / FES Software Technologies

Gua d a dge / S So t a e 11 immixTechnology / Pointsec Mobile

Technologies

Pointsec FDE Software 12 GTSI Corp / Credant Technologies Mobile Guardian FES Software

(11)

DARTT BPA Advantages

ƒ All awarded offers are FIPS 140-2 validated - vendor FIPS 140-2 Confirmation form on file in the

GSA/SmartBUY Program GSA/SmartBUY Program

ƒ Licenses are transferable within a federal agency and include secondary use rights

V l i i i b d ti f 10 000 33 000

ƒ Volume pricing is based on tiers for 10,000, 33,000, and 100,000 users

ƒ Competitive spot discounting is encouragedp p g g

ƒ Five option years after award date: June 15, 2007 ƒ The BPAs were awarded through a full and open

competition The 103 technical requirements were competition. The 103 technical requirements were provided by all federal agencies and were evaluated by an interagency USG team of information

/ t t k d f SME

References

Related documents

It describes the technology behind the XtremIO encryption solution and how the architecture combines encryption with XtremIO’s unique data protection and Inline Data

These include: direct provision of justice services, either in substitution of, or co-production with, the state, for example, pro-bono work for individuals lacking legal

beyond initial acquisition to expand revenue by enabling adoption, consumption, retention— technical expertise must be part of the process More than anything else, success in the

According to the Information Systems Audit and Control Association (ISACA), “The most critical aspect of encryption is the determination of what data should be encrypted

into SED management storage system Ships to customer SysAdmin installs new volume / storage system in data center SysAdmin initializes new system (authentication key,

Based on guidance from editorial staff supports all editing assignments, for both internal and external communications to include: newsletters, press releases, brochures, TV and

Encryption at the device level — array, disk, or tape — is a sufficient method of protecting sensitive data residing on storage media, which is a primary security risk

Unencrypted data Encrypted data Management traffic RSA Key Manager Client RSA Embedded Key Manager Server Service Processor...