Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts

Thursday, September 8, 2011

Win7/Office 2010 Deployment Office 2, Days 3 & 4

Last week I covered the first two days of our Window 7 & Office 2010 deployment in this blog. Today I am going to tell you how we close the deal during days 3 and 4.

Day 3. Closing the Deal
After a relaxing night closed out with a walk at one of Hilton Head beaches’ shore we were re-energized and it showed as soon as we got to the building. The first group, the support team, got to the office very early to be available to help the office staffers that got newly imaged PCs with the new OS and Office Suite as well as some new or upgraded applications, including our iManage DMS application. The deployment team arrived to the office later that morning to continue working on re-imaging machines and addressing escalated issues.

“Any change, even a change for the better,
 is always accompanied by drawbacks and discomforts.”
Arnold Bennett

Yes, there was a lot of change and the next few days, and weeks will bring a lot of adjustment for our firm while dealing with a new interface that touches pretty much everything they do in a daily basis. However, I can’t emphasize enough the great performance delivered by our Training Team. This showed during the whole day. While there were a lot of different activities going on at the same time, the day went very well; I really had expected more issues and questions from our users but they held up and dealt with the massive change extremely well and they actually did bring up some very valid questions. Once again, Kudos to our Training Team here, and they were not done yet.

After a nice group lunch in the office the big test for our team arrived; attorney training. The challenge wasn’t only to engage them and keep them involved but also efficiently deal with the many activities going on at the same time. We had two people doing floor support, two folks conducting attorney training, and three re-imaging the rest of the machines of those in training. Once I finished imaging one of the machines assigned to me I saw the need of switching my role into that of a Project Manager. Issues were still coming up and the vast majority was being efficiently and promptly handled by the support team, while some would need more advance troubleshooting and help from the engineers back at The Mothership. Thus, I saw the need to become the central information repository and I started to centrally compile all issues in our log dedicated to that. We always intended to approach the project this way but we had to deviate a bit from it for many reasons. However, we were able to quickly adapt and react to the new situation and get that PM role going again, which will now be part of all future role outs as it should. The PM will focus on being the “Central Communications Center” as well as the data collector so everyone can stay focused on their tasks. So I started walking around and making sure that everyone was doing what they were supposed to while collecting information that we needed to pass on to the rest of the team.

At the end, we were able to re-image all remaining machines and complete both support and training. It was a long day for most, but the preparation and planning that went on for months paid off again. I think that the main challenge for most was adjusting to the new iManage interface and Idol search engine as well as the obvious adjustment to the Office Ribbon.

Day 4. The Attorneys & Training; Need I Say More?
I do indeed! But this time I wasn’t impressed because of the amazing job that our trainers did. They really engaged the attorneys who also did a great job embracing the new interfaces and really going for it and trying to make the most out of the new systems.

“Change brings opportunity.”
Nido Qubein

As I mentioned these attorneys were really trying to adjust and make the most out of the system. They had great comments about the iManage EMM plugin for email management, which was not being used by all of them; some were exploring the IDOL search engine and began to like it a lot; heck we had attorneys using Win7 Snipping Tool!!! One of then used this tool to create a Memo and here is how she summarized her experience: “This upgrade has revolutionized my day! I did a two-page memo faster than I've ever been able to do before”. Now, getting this type of comment on Day One, I mean like the morning after the attorney was trained and facing massive change?…Priceless, for everything else, there are Windows XP & Office 2003!

Now, there were still issues and one that we are looking at how to better handle in the future is synchronizing OST files over the WAN. When a person travels to a remote office and logs for the first time to a different computer, Outlook will start synchronizing its caching and could potentially cripple the bandwidth to the office depending on the situation. The way we approached the initial deployment was by bringing OST file from last production day, in this case Friday, with us so that we could sync up locally without going over the wire. The switch to cache mode presents a new challenge not only during the migration but on an ongoing basis going forward, especially for offices with small bandwidth capacity. I will be looking at how our Riverbed Steelhead can help here.

Thanks to the amazing work of the support team, the deployment team was ready to return home by 3:00 pm. Our trainers remained behind and assumed support responsibilities the rest of the week which went very well. In fact, I’ve been checking with our service desk analysts and the call volume from the offices that have been converted have been very low according to them.

We are working on the next deployment which starts this upcoming weekend in our main office here in Columbia, SC. This will be the largest deployment so far and will tell us a lot for the rest of the way but I am confident that our team will deliver once again. From this point on I will be
occasionally posting updates about the whole project as we go on. I will continue to be in some of the deployments as either the Operations Manager or Project Manager. Meanwhile, my team is coming behind the Win7 team rolling out Endpoint and Media Encryption using Credant's Mobile Gurdian at the offices that have been migrated to the new OS already and I will be blogging about that project as well.

Sunday, February 6, 2011

Technical Safeguards for Legal regarding HIPAA

In February 2010 the Legal Industry got hit with a pretty big compliance issue when the HI-TECH Act made changes affecting HIPAA Business Associates. The legal world gets directly affected by these changes because Law Firms that work with Covered Entities through their Health Care, Litigation, and perhaps other practices, become Business Associates. I will not go any further into details of the actual specifications of the law. Instead, I will focus on what you could do to implement Technical Safeguards to protect Electronic Protected Health Care Information, ePHI. Meanwhile, I will refer you to ILTA’s HIPAA Rules for Law Firms article enclosed in the Peer to Peer edition of March 2010. Notice that I am only dealing with Electronic PHI here, and hard copies of this form of data deserve attention as well.
Protecting that pesky ePHI and THE FIRM
HIPAA brings new Information Management and Information Security challenges to the legal industry and its technology practitioners but it is also a good opportunity to protect your firm as a whole, which I have been preaching since engaging in the HIPAA project because of my background on security. Any regulatory compliance requirement that your firm is going through is an opportunity for the Technology Department to build a strong security program around it. You may not need to apply specific HIPAA safeguards to the whole firm, but I can assure you that there are other regulations that you need to comply with, and if that is not the case, it is just common sense, especially with new regulations around Personal Identifiable Information around the nation.

Since we are focused on HIPAA here, let’s take care of the Health Care practice and the HR area that deals with ePHI and problem solved you may be thinking. Wrong! Expect MANY folks outside the Health Care practice to be BAs because involvement in different Matters. I encourage you to conduct a survey asking who handles any type of PHI, whether electronic or not. I bet you will be astonished with the results.
BUT WHERE IS THAT DATA? I mean, really. Do you know where all the ePHI is? If you do, then I salute you. Oh, and I know that you are thinking about your Document Management System, DMS, your Financial Systems, and your File and Print servers. Is that it? Can you probe it? How about laptops, desktops, and other servers? This is an ongoing process and the stepping stone of any implementation that follows. You can’t protect something that you are not aware of. It is important to understand that you must be able to log and audit your systems in order to probe compliance. Thus, my inclination for systems that meet that critical requirement.
Today there are tools that can scan your network and leverage built-in dictionaries and rules that help you identify compliance specific data. They are often referred as DLP tools (Data Leak/Loss Prevention tools) however, don’t rely on them completely. Talk to the data owners and users as well. I have found over the years that users are the best resource that you can use while building your security program.
We found the data, let’s build the Fort
Let’s start with Access Control. Make sure you understand your network as a whole, especially your Active Directory (AD) Security Groups and other security elements of it. I am sure that you follow industry best practices, but can you audit and probe that? Implement a strong Security Information and Event Management tool, SIEM, which goes beyond traditional Log Aggregation. Products such as TriGeo, and LogRythim have built-in “intelligence” that not only can help you log and audit, but also aid your Change Management strategy, something I am big on as stated in my last post. You will gain visibility into any changes made into your security groups. There are also AD specific auditing tools that can aid on this area and may be more accessible such as ManageEngine products.
Additionally, take a look at your Ethical Walls approach and see if you can extend it beyond your Records department. It is extremely important that there is ongoing communication and collaboration between IT and Records during this process so that you can expand your strategy to areas of IT such as DMS, and Financial systems through software like RBRO, WincWall or IntApp, in addition to Risk Management built-in features in your DMS or Financial systems.
Data in Motion is not only email
We often think of Data in Motion as email, so let’s start there. My background in Health Care taught me one thing: securing ePHI moving through your messaging system could become a nightmare if not thought thoroughly. In my experience I’ve found that the first thing to mind is TLS, which is a great encryption method, yet unmanageable in mid-size and large environments. The same applies to a Certificate based PKI approach. In both cases, the challenge is managing all those certificates and keys. Furthermore, you’ll have to deal with those smaller Health Care practices that don’t have an IT Department capable of setting up managing their end.
A third solution includes full email encryption products that deliver encrypted messages to the recipient’s inbox. Products such as Cisco’s IronPort, ProofPoint, or the very well-known in the Legal vertical Mimecast deliver messages either as encrypted attachments or with a link that will redirect you to a secure site where you can read your messages and take action on them. I highly favor this approach because they are centrally managed, more scalable, and have stronger logging and reporting capabilities. However, be prepared to provide clients with the other two alternatives. You will come across end-users that will hate having to go through an extra step to “just read an email”.
Then there is the new world of mobility, which includes Laptops in all forms, USB drives and other removable media, Smartphones, tablets and the list keeps growing.
You can address issues around laptops and removable media with Encryption tools such as those offered by Check Point, PGP, or Credant, or the free, yet extremely strong TrueCrypt. You will have to pick “your pain” when it comes to encryption. If you choose to go with a Full Disk Encryption approach then you are going to have to deal with pre-boot authentication, which can become a pain when performing trivial tasks such as troubleshooting a system that needs to be rebooted, or deploying software upgrades (in addition to the adoption opposition). If you go with just File Level Encryption only, your devices may still be exposed to Brute Force attacks. And then, there’s Credant’s interesting approach, which encrypts at the file level, yet, it protects the machine’s registry that deal with AD Security database and swap files, which protects the device against access attacks. I really like this approach.
Encryption tools also protect removable media such as USB drives and even SIM cards in Smartphones by deploying policies that can limit device access, white list them so that only approved devices are allowed, and encrypt data in a similar way as previously described. Just make sure that you are aware of what your mobile device float looks like and that you set expectations with regards to client involvement, meaning, what to do when you send data and devices to each other.
Smartphones are also a concern, and although most people think of the problem in regards to email I think that we need to look further and create a strategy that address security concerns around it as a whole, just like you handle laptops. As stated in 2010 ILTA Conference session, Strategies for Managing Disparate Devices in Your Mobile Fleet, these devices are PLATFORMS, so you must threat them as such. I will dedicate a different post to this topic, but for now, know that there are tools that can help you manage these devices by separating corporate data from personal data and in turn, encrypt and control the business data and take action such as deny access or remote wipe the firm’s data. Examples include Good Technologies, MobileIron and Zenprise. McAfee and TrendMicro among others, are also coming up with AV Software for these devices, which in my opinion, will be a must have by the end of this year.

If your firm is dealing with HIPAA, then take this an opportunity to enhance your Information Security program, which in my opinion, has been traditionally too loose in the Legal sector. I will be blogging later on Information Security Policies and Procedures, as well as Disaster Recovery, which are important areas to achieve HIPAA compliance.
What is your firm doing to protect Electronic Protected Health Care Information? Moreover, what other regulations are hitting your firm?