Compliance
With new state privacy laws, industry regulations such as PCI, and updates to HIPAA and other federal mandates stemming from the HITECH Act and ARRA (also known as the 2009 Stimulus Act), organizations face an increasingly stringent and more complex compliance landscape. In addition to the embarrassing public disclosures and the high costs of remediation, a privacy breach can distract IT staff from their business tasks by requiring them to constantly respond to auditors and regulators.
Eliminating Compliance Risks with Managed Secure USB Drives
USB flash drives pose a unique compliance risk. Their small size makes them easy to conceal and easy to lose. The best way to mitigate this risk is by ensuring all data stored on your organization's flash drives is encrypted. In fact, many privacy laws now either mandate encryption or provide "safe harbor" if data on a device was encrypted at the time it was lost or stolen. You cannot achieve compliance without management, which includes the ability to:
- Know to which employee the drive was issued
- Know when and where that person used it
- Prove the device has not been accessed in the event it is lost or stolen
IronKey addresses compliance needs with an enterprise-class solution for protecting mobile data that combines secure hardware-encrypted flash drives with central management software.
Always-on Encryption
IronKey Enterprise devices encrypt data in hardware whenever the user transfers files onto the drive. The user cannot turn off encryption or circumvent it in any way. This "always-on" encryption not only ensures that an organization's critical data is always protected but also makes compliance with PCI and state and federal regulations virtually automatic. No software or drivers need to be installed-your users can use IronKey devices on Mac, Linux, and Windows computers-even on their home computers-and your organization's critical data is always protected.
The IronKey Cryptochip protects data stored on IronKey drives with AES 256-bit hardware encryption. IronKey drives are the first to meet the U.S. government's strict FIPS 140-2 Level 3 criteria for cryptographic technology. The result is the strongest mobile data protection available.
Central Management and Secure Device Recovery
In addition to central management software that includes audit trails and other capabilities necessary for compliance, IronKey Enterprise provides Secure Device Recovery. This function allows administrators to recover the contents of a drive if the end-user loses the drive, or leaves the company with it, thereby helping to maintain and prove custody of data stored on a drive. There are no back doors to this device recovery system.
The central IronKey management server also allows you to revoke Admin status if the administrator leaves the company.