Forensic Science Service
 |
Customer Statement - Dave Debenham, Forensic Science Service |
Dave Debenham is the XP Project Technical Lead at the Forensic Science Service
" During the pilot roll-out of XP across our organisation, we found that the 'plug and play' element posed a major risk to our network and so we began investigating solutions that could help us to minimise the risk from USB devices while also enabling access to those that required it. We have 2 infosecurity staff with responsibility for management of access rights and new additions of hardware for more than 2,000 FSS employees.
I evaluated three products, [...] and Lumension® Device Control. I was looking for a product that would allow us to manage granular access to devices, so that individuals could be given authorised access to specific removable storage media, while the majority were blocked from uploading or downloading data in this way. Lumension Device Control was the only product that would allow me to give certain members of our organisation access to specific devices. For example, I can enable digital cameras to be connected to a desktop or laptop by an authorised employee for the purpose of uploading scenes of crime photographs. Because Lumension Device Control integrates with Active Directory, we can provide authorised USB device access to specific personnel, no matter where they log in. It is crucial that those people are able to access these devices wherever they are working within the organisation.
Lumension® Device Control works on a centrally managed default deny basis where only authorised personnel are allowed to connect specified removable devices to the organisation's desktops and laptops, all other access is denied. We began deploying in January 2005 following several months' testing and have currently deployed 2, 200 licences of Lumension® Device Control.
I don't endorse products lightly, but I have been really impressed with the functionality provided by Lumension® Device Control and with the quality of support provided by SecureWave. FSS has a government restricted network and links to other government networks such as the GSI and CJX (Criminal Justice Extranet). We are using AV software from Sophos, but we are also currently trialling Lumension® Device Control, which applies a default deny environment to all executable files and applications. So if a file is not specifically authorised it will not be permitted to run on the network. This prevents any spyware, malware or Trojans from executing. "