The Trusted Computing Group on Thursday released final versions of three specifications to strengthen data protection, help organizations comply with regulations, and secure corporate information.
The specifications for storage devices offer a blueprint for developing self-encrypting hard drives that lock data, can be immediately and completely erased, and can be combined with the Trusted Platform Module. Major storage vendors, including Hitachi, Toshiba and Seagate, support the specifications.
The Privacy Rights Clearinghouse estimates that in the United States alone, 251,154,519 records have been lost or stolen since January 2005. What’s more, some 12,000 notebook PCs are lost or stolen in airports in the United States, with only 33 percent recovered.
“Lost and stolen data costs industry and consumers hundreds of millions of dollars, not to mention loss of credibility, legal issues, and lost productivity,” said Robert Thibadeau, chairman of the Trusted Computing Group’s storage work group. “TCG’s approach to trusted storage gives vendors and users a transparent way to fully encrypt data in hardware without affecting performance so that data is safe no matter what happens to the drive.”
Minding Data-Protection Laws
The Opal specification outlines minimum requirements for storage devices in PCs, while the Enterprise Security Subsystem specification deals with data centers and high-volume applications. The Enterprise specification defines encryption of data and supports access control.
The Storage Interface Interactions specification covers how the TCG’s existing Storage Core specification and other specifications interact and sets standards for storage interfaces and transports.
“With 48 states and many countries enforcing data-protection laws, it has become crucial for enterprises to protect all data to avoid fines, lawsuits or even being put out of business,” said Jon Oltsik, senior analyst for the Enterprise Strategy Group. “Encryption with authentication directly in the drive or enterprise storage devices, as outlined in the Trusted Computing Group specifications, is one of the most effective…