skip to main content
10.1145/1449956.1449964acmconferencesArticle/Chapter ViewAbstractPublication PagesuccsConference Proceedingsconference-collections
research-article

PGP whole disk encryption: blazing trails in IT security at UW Medicine

Published:19 October 2008Publication History

ABSTRACT

The Department of Surgery at the University Of Washington School Of Medicine is faced with the challenge of providing IT security to faculty, researchers, and staff within a clinical hospital environment and at multiple sites. Many departmental faculty and staff use laptops running Windows XP and often find it necessary to travel to multiple locations throughout the day or week. Additionally, regulations such as the Health Insurance Portability and Accountability Act (HIPAA) and the Family Educational Rights and Privacy Act (FERPA) mandate the protection of protected health information (PHI) and student data that many members of the department interact with as a normal part of their work. Such data stored on departmental laptops must be secured. Concerned with data security, the department is deploying PGP Universal in order to protect this fleet of laptops with a centrally managed, whole disk encryption solution.

A centrally managed whole disk encryption solution was desired for both Windows XP and a small number of Macintosh laptops, but not available for the latter. The Department of Surgery IT Services Group (ITSG) selected PGP Universal for the Windows-based solution and monitors PGP Corporation's ongoing development of a Mac OS X whole disk encryption solution. ITSG staff tested PGP and a deployment process was developed in the hopes of avoiding technical problems. Minor installation problems that did occur were found to be the result of computing staff's deviation from installation procedures. The amount of time required to deploy the solution across the department was underestimated; the project has taken additional time for several reasons, including the difficulty in coordinating installations with a mobile workforce; a number of competing, large scale products; and possibly the ITSG organizational structure. While the use of PGP whole disk encryption has necessitated a change in behavior for both laptop users and ITSG staff, these changes are minor and can be addressed with careful planning and forethought.

References

  1. About UW Medicine. http://uwmedicine.washington.edu/Global/AboutUWMedicine/, (retrieved May 20, 2008)Google ScholarGoogle Scholar
  2. Apple Inc., FileVault. http://www.apple.com/sg/macosx/features/filevault/, (retrieved May 31, 2008)Google ScholarGoogle Scholar
  3. Check Point Full Disk Encryption. http://www.checkpoint.com/products/datasecurity/pc/index.html, (retrieved May 31, 2008)Google ScholarGoogle Scholar
  4. Encrypting File System. http://technet2.microsoft.com/windowsserver2008/en/library/69f04dd7-bced-4079-84e9-095b8dc563991033.mspx?mfr=true, (retrieved May 31, 2008)Google ScholarGoogle Scholar
  5. Halderman, J., Schoen, S., Heninger, N., Clarkson, W., Paul, W., Calandrino, J., Feldman, A., Applebaum, J., and Felten, E. Lest we remember: Cold boot attacks on encryption keys. April 2, 2008. http://citp.princeton.edu/pub/coldboot.pdf, (retrieved June 1, 2008) Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. McCullagh, D. PGP: Whole disk encryption for Mac OS X is in 'active development'. February 11, 2008. http://news.cnet.com/8301-10784_3-9869812-7.html, (retrieved May 31, 2008)Google ScholarGoogle Scholar
  7. PGP Corporation, PGP Universal Server. http://www.pgp.com/products/universal_server/index.html, (retrieved May 20, 2008)Google ScholarGoogle Scholar
  8. PGP Corporation, PGP Whole Disk Encryption. http://www.pgp.com/products/wholediskencryption/index.html, (retrieved May 20, 2008)Google ScholarGoogle Scholar
  9. PGP Corporation, PGP Whole Disk Encryption for Mac OS X. http://www.pgp.com/mac, (retrieved June 20, 2008)Google ScholarGoogle Scholar
  10. UW Department of Surgery. http://depts.washington.edu/surgery/about/index.html, (retrieved May 20, 2008)Google ScholarGoogle Scholar

Index Terms

  1. PGP whole disk encryption: blazing trails in IT security at UW Medicine

            Recommendations

            Comments

            Login options

            Check if you have access through your login credentials or your institution to get full access on this article.

            Sign in
            • Published in

              cover image ACM Conferences
              SIGUCCS '08: Proceedings of the 36th annual ACM SIGUCCS fall conference: moving mountains, blazing trails
              October 2008
              360 pages
              ISBN:9781605580746
              DOI:10.1145/1449956

              Copyright © 2008 ACM

              Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

              Publisher

              Association for Computing Machinery

              New York, NY, United States

              Publication History

              • Published: 19 October 2008

              Permissions

              Request permissions about this article.

              Request Permissions

              Check for updates

              Qualifiers

              • research-article

              Acceptance Rates

              Overall Acceptance Rate123of170submissions,72%
            • Article Metrics

              • Downloads (Last 12 months)3
              • Downloads (Last 6 weeks)0

              Other Metrics

            PDF Format

            View or Download as a PDF file.

            PDF

            eReader

            View online with eReader.

            eReader