"IMPORTANT ANNOUNCEMENT - November 2010 SanDisk FIPS Cruzer Enterprise EOL Notification"...Read More
SanDisk Cruzer Enterprise

2008-04-12

Cruzer Enterprise Potential Vulnerability, December 2009


SanDisk has recently identified a potential vulnerability in the access control mechanism of its Cruzer Enterprise flash drives series and has provided an update to address the issue.

As a result, SanDisk has made software updates available to all existing Cruzer Enterprise devices. In addition, all Cruzer Enterprise USB flash drives being shipped to customers as of today contain the product update.
Important Note: This issue is only applicable to the application running on the host and does not apply to the device hardware or firmware.

Devices to which this change applies:
Cruzer Enterprise, CZ22 - 1GB, 2GB, 4GB, 8GB
Cruzer Enterprise FIPS Edition, CZ32 - 1GB, 2GB, 4GB, 8GB
Cruzer Enterprise with McAfee, CZ38 - 1GB, 2GB, 4GB, 8GB
Cruzer Enterprise FIPS Edition with McAfee, CZ46 - 1GB, 2GB, 4GB, 8GB
Up to versions 2.0.5.33 or 2.5.6.292. Newer versions are already updated.

Recommendations:
To implement this change, SanDisk recommends that users run a dedicated tool to identify their device version and direct them to the corresponding update version. This procedure is designed to be performed locally by users to streamline the updating process.

Therefore, SanDisk recommends that users:
Fill in the online form here: http://www.sandisk-enterprise.com/update2/. This will direct users to a downloading site.
Download the updater selector application and the Quick Reference Guide with installation instructions.
Change the Cruzer Enterprise USB flash drive password Support:
The SanDisk support team is ready to answer any questions you may have and is available at support@sandisk.com


2008-04-12

Cruzer Enterprise Potential Vulnerability


SanDisk has recently identified a potential vulnerability in the access control mechanism and has provided a product update to address the issue. SanDisk customers were proactively notified and have been given the support required for updating their Cruzer Enterprise drives.

In the past few days several news sites have reported on this incident. Most coverage addressed the issue at hand and referred to the SanDisk web site for the resolution. Some reporters and bloggers even approached SanDisk for a response.

However, some of the coverage was simply wrong and has caused confusion in the market.

To reassure SanDisk customers that their existing and future Cruzer Enterprise devices are safe and secure, the following inaccurate claims need to be addressed:

1. "There is an architecture flaw in the Cruzer Enterprise security design which generates a static unlock code"
There is no architecture flaw in the Cruzer Enterprise security design. As mentioned in previous communications, there was an error in one of the host application algorithms used to generate a random key that is then verified against a derivation of the user password stored in hardware.
A fix for this has been made available to customers, and new drives incorporate the updated application.

2. "The Cruzer Enterprise relies on a host-side software for verifying the correctness of the users password" Key verification for unlocking the device is done in hardware and not by a software application on the host. The Cruzer Enterprise secure USB drive uses unique random AES encryption keys that are generated on the device during device initialization. These encryption keys are stored in hardware and cannot be extracted from the device.

3. "The Cruzer Enterprise has no measures against Brute Force attacks"
The Cruzer Enterprise secure USB drive is designed to prevent brute-force attacks ("password replay attacks") by storing the brute-force counter in the hardware cryptographic chip. Preserving customer security and product reliability continues to be a top priority at SanDisk and SanDisk will continue to work diligently with customers to perform the product update in a timely manner.
SanDisk now offers its central management and control system (CMC) free-of-charge for a period of three months to support the updating process in large organizations (for more information please contact ent.support@sandisk.com) SanDisk is a vertically integrated designer and manufacturer of flash products and has a long standing security practice. This ensures that its security products utilize best-of-breed technologies and hardware as we are not a mere integrator of third-party components.
With offices and manufacturing facilities around the world, SanDisk customers have access to a global distribution and support infrastructure and can be reassured that they are working with the global leader in flash memory cards.


2008-04-12

SanDisk Cruzer Enterprise Product Update Announcement


As we continue to improve our operational execution, we are focusing on streamlining our product offering and go to market strategy. As a result, we will consolidate the Enterprise product line and offer two superior hardware platforms.

1. What does this mean?
This will enable us to address the market with a strong, cutting edge line of products, while reducing confusion and complexity of Non FIPS Products lines.

2. Which products will be available for sale?
Starting April 1st, all of our secure USB encrypted drives will be FIPS certified, as we recognise the need to offer our customers the most secure solutions on the market. We will offer the drives in 2 varieties, with or without malware protection.

The table below describes our updated secure USB drive offerings.

Cruzer Enterprise FIPS Capacity
SDCZ32-001G-A75 1GB
SDCZ32-002G-A75 2GB
SDCZ32-004G-A75 4GB
SDCZ32-008G-A75 8GB
Cruzer Enterprise FIPS W/Anti Malware
SDCZ46-001G-A75 1GB
SDCZ46-002G-A75 2GB
SDCZ46-004G-A75 4GB
SDCZ46-008G-A75 8GB

3. Will the old products still be supported?
Cruzer Enterprise will continue to be supported through the end of the 2-year warranty applicable to our USB drives.

4. Which products will be discontinued?
The following SKUs will be removed from the Cruzer Enterprise Product line:

These products will enter end of life process.
SKU Description
SDCZ22-001G-A75 Cruzer Enterprise 1GB
SDCZ22-002G-A75 Cruzer Enterprise 2GB
SDCZ22-004G-A75 Cruzer Enterprise 4GB
SDCZ22-008G-A75 Cruzer Enterprise 8GB
SDCZ38-001G-A75 Cruzer Enterprise 1GB With Malware protection
SDCZ38-002G-A75 Cruzer Enterprise 2GB With Malware protection
SDCZ38-004G-A75 Cruzer Enterprise 4GB With Malware protection
SDCZ38-008G-A75 Cruzer Enterprise 8GB With Malware protection

5. What about CMC?
The above changes have no affect on CMC, our leading management console for secure USB drives. This product will continue to be offered, developed and supported as before. However, we will be imposing a minimum order quantity of 20 licenses for CMC.

6. If you have customers wanting to buy the CZ22 SKU, What should I offer them now?

The below conversion table shows the migration path to be offered
Previous SKU        Replaced by
SDCZ22-001G-A75    SDCZ32-001G-A75
SDCZ22-002G-A75    SDCZ32-002G-A75
SDCZ22-004G-A75    SDCZ32-004G-A75
SDCZ22-008G-A75    SDCZ32-008G-A75
SDCZ38-001G-A75    SDCZ46-001G-A75
SDCZ38-002G-A75    SDCZ46-002G-A75
SDCZ38-004G-A75    SDCZ46-004G-A75
SDCZ38-008G-A75    SDCZ46-008G-A75

For further information please contact the Cruzer Enterprise Division on +44 1189 323 499

2008-04-12

SANDISK ANNOUNCES UPDATED ENTERPRISE SOLUTION OF SECURE USB FLASH DRIVES AND MANAGEMENT SOFTWARE


  • Central Management and Control (CMC) Software Version 3.0 Increases Security and Enables More Flexible Data Management of SanDisks Cruzer Enterprise Product Line.

  • All Cruzer Enterprise Secure Flash Drives are now FIPS Certified.


  • EnterpriseFIPS-Edition8GB-Cap-LeftHiRes Milpitas, Calif., April 27, 2009 - SanDisk Corporation (NASDAQ:SNDK) today announced that all Cruzer Enterprise models currently shipping are FIPS certified, offering corporate and government IT departments a valuable tool in managing their secure hardware ecosystem. In addition, SanDisk has released Central Management and Control (CMC) software version 3.0, equipping IT professionals with more tools for distributing, protecting and recovering critical data.

    Streamlined hardware family offers industry-leading security.
    SanDisks Cruzer Enterprise secure USB flash drives now come in two forms: standard Cruzer Enterprise and Cruzer Enterprise with McAfee Malware Protection.

    Both Cruzer Enterprise products feature FIPS (Federal Information Processing Standard) 140-2 Level 2 certification for encryption, a standard set by the National Institute of Standards and Technology (NIST). FIPS certification confirms that a drive has met NIST standards for design of the cryptographic module, for the strength of encryption algorithms and resistance to physical intrusion. The encrypted flash drive imposes mandatory access control on all files, which are stored in a secure partition that implements 256-bit hardware-based AES USB encryption

    In addition to FIPS protection, Cruzer Enterprise products with McAfee security software help defend users from infection with an automatic anti-malware scan that prohibits file transfers to the secure USB drive when it detects infection on a host PC.

    New software version enables flexible management of secure storage drives.
    Utilizing the unique hardware and embedded software capabilities of Cruzer Enterprise secure USB flash drives, CMC software has been used by government agencies, healthcare organizations and enterprises for years. The CMC device agent resides on a company-issued Cruzer Enterprise drive, giving corporate IT departments a powerful tool for lifecycle management of the device - including deployment throughout the organization, password recovery and renewal through the network, central back-up and restore, central usage tracking and remote termination of lost drives.

    "Protecting critical data is a major priority for corporate IT professionals, and SanDisk Enterprise offers a two-pronged approach to meet that need," said Roy Ramati, vice president, enterprise division, SanDisk. "Cruzer Enterprise encrypted flash drives provide secure and reliable high-capacity storage, while CMC 3.0 software offers advanced enterprise data management for those drives. This combination ensures that even if a drive is lost or stolen, the companys sensitive information will remain secure and recoverable.

    CMC version 3.0 offers new tools for IT professionals, including:
    Application and content distribution: CMC 3.0 allows central distribution of virtualized productivity applications to Cruzer Enterprise secure flash drives through the network. New applications appearing in the Cruzer Enterprise launchpad are easily accessed through an icon in the system tray, enabling users to introduce new applications rapidly without having to initiate an installation process or bring their drives to the IT department. CMC 3.0 also allows central distribution of content files to relevant users or groups in the organization, ensuring they get easy and immediate access to important, up-to-date documents.

    Enhanced password policy control: Passwords can now be set to expire after a period of time determined by the IT department. This increases USB security by reducing the risk of unauthorized users gaining access to longstanding passwords. CMC 3.0 also offers the option of synchronizing with Active Directory password policies.

    Expanded reports: IT administrators can create pre-defined reports on user activity, and access a wizard for creating dynamic reports on demand. This gives the IT department new tools for uncovering violations of the organizations data security policies and for providing confirmation of regulatory compliance through an enhanced audit trail.

    Streamlined deployment and user provisioning: Cruzer Enterprise drives can now be remotely configured from any corporate PC without pre-installation of a software agent. This enhances overall user productivity and shrinks the time and effort required to add new drives, especially in large organizations with multiple locations and many remote workers.

    Existing CMC customers can enrol in an upgrade program to the new version through SanDisk authorized partners.

    SanDisk is a leader in providing innovative, secure USB flash drives and management solutions for the mobile workforce in enterprises and government agencies. SanDisks enterprise solutions allow IT managers to extend the enterprise security perimeter to mobile storage and boost employees productivity.

    About SanDisk: SanDisk Corporation, the inventor and worlds largest supplier of flash storage cards, is a global leader in flash memory - from research, manufacturing and product design to consumer branding and retail distribution. SanDisks product portfolio includes flash memory cards for mobile phones, digital cameras and camcorders; digital audio/video players; USB flash drives for consumers and the enterprise; embedded memory for mobile devices; and solid state drives for computers.

    2008-04-12

    SANDISK OFFERS McAFEE ANTI-MALWARE TECHNOLOGY IN SECURE USB FLASH DRIVES


    Always On safeguard blocks malware even outside of the firewall, Automatic scan prohibits file transfers to secure USB drives from infected PCs.

    LAS VEGAS, NEVADA, Oct. 21, 2008 -SanDisk Corporation (NASDAQ: SNDK) and McAfee, Inc. (NYSE: MFE) today announced SanDisk Cruzer Enterprise with anti-malware protection from McAfee. In addition to protecting corporate USB flash drive users from data leaks, the solution includes the McAfee Scan Engine, which offers advanced heuristic analysis for comprehensive detection of both known and unknown threats. Expected to be available before years end, this Always On safeguard blocks malware from entering the secure USB flash drive even when the device is used outside of the firewall.

    Information about SanDisk Cruzer Enterprise is available at SanDisks booth (#107) at Focus 08, a security conference sponsored by McAfee that is underway this week at the MGM Grand in Las Vegas through Thursday.

    "SanDisk Cruzer Enterprise is an ideal solution for the mobile workforce and for IT departments concerned with data security, because it allows employees to have access to data everywhere and yet be fully protected," said Roy Ramati, vice president and general manager, Enterprise Division at SanDisk. "Adding McAfees technology to our security solutions for the enterprise enables our customers to extend their security perimeter to mobile storage."

    Cruzer Enterprise with McAfee security protects users from infection with an automatic anti-malware scan that prohibits file transfers to the secure USB drive when it detects infection on a host PC. Malware, short for malicious software, is a program that is intended to disrupt a computer system by introducing a harmful code such as a virus, worm or Trojan horse. The addition of McAfee Scan Engine and virus definition files (DATs) prevents malware from attaching itself to the portable drive and in turn, infecting the internal enterprise host. The scan engine examines every file saved or copied to the USB flash drive.

    "With todays increasingly mobile work force and the speedy proliferation of new threats, its just as vital for organizations to protect their portable devices from malware as it is to secure their perimeter" said Christopher Bolin, executive vice president and chief technology officer, McAfee. "The McAfee Scan Engine has been battle-tested over many years and is the foundation of McAfees anti-malware solutions. SanDisk Enterprise Cruzer customers can rest assured that they have reliable and accurate detection from malicious code."

    Cruzer Enterprise safeguards all files stored on the drive with advanced hardware-based 256-bit AES encryption. Users are required to create a complex password during the set-up process. The combination of encryption and password protection makes it extremely difficult for unauthorized users to access data should the drive be lost or stolen.

    SanDisk CMC server software provides lifecycle management for Cruzer Enterprise drives, including password recovery and renewal through the network, remote termination of lost drives, central back-up and restore, and central usage tracking. This means data is not lost when a drive is lost, and IT administrators can provision a replacement flash drive with user files stored on the network.

    SanDisk, a global leader in USB flash drives, is driving the convergence of flash drive security, authentication and virtualization through its Enterprise Division to create a comprehensive solution for mobile professionals in enterprises and government agencies.


    2008-04-12

    Howard County General Hospital in Maryland Selects SanDisk Secure Flash Drives and Management Software


    Confidential Medical And Organizational Data Now Secured With SanDisk Cruzer Enterprise USB Flash Drives, Managed By SanDisk CMC Software

    MILPITAS, CALIFORNIA, July 14, 2008 SanDisk Corporation (NASDAQ:SNDK) today announced that Howard County General Hospital in Columbia, Maryland, has selected SanDisks Cruzer Enterprise secure USB flash drives and Central Management & Control (CMC) server software to protect highly confidential medical and organizational data.

    Part of the Johns Hopkins Medicine health care system, which includes the prestigious Johns Hopkins University School of Medicine, Howard County General Hospital (HCGH) is a comprehensive medical center providing services to more than 165,000 people a year, with a staff of 1,700 full-time and part-time employees, as well as more than 800 physicians and other allied health professionals.

    HCGH recently purchased SanDisk Cruzer Enterprise drives to provide on request to managers in all departments of the hospital, and subsequently purchased SanDisk CMC software to manage those drives through the hospitals network.

    "Few types of information are more confidential than patient records, making data security a top priority in health care," said Rick Edwards, Senior Director and Chief Information Officer for HCGH. "We selected the SanDisk Cruzer Enterprise drive because security is not an option - all files are encrypted and password protected. We added SanDisk CMC software so our IT staff can have more control over data stored on USB flash drives, as well as the ability to remotely supervise day-to-day tasks such as password management and backup."

    "We are honored that Howard County General Hospital, a leader in adopting new health care IT solutions, is turning to SanDisk to help make data in use more secure," said Roy Ramati, Vice President and General Manager of the Enterprise Division at SanDisk. "Looking beyond security, we believe HCGH will appreciate how CMC can increase the IT staffs visibility into how the drives are used."

    SanDisk Cruzer Enterprise flash drives protect all files stored on the drive with advanced hardware-based 256-bit AES encryption. Users are also required to create a complex password during the set-up process. The combination of encryption and password protection makes it extremely difficult for unauthorized users to access data if the drive is lost or stolen. Cruzer Enterprise is also fast, with read speed of 24 megabytes (MB) per second and write speed of 20 MB/sec1.


    2008-04-12

    SanDisk Survey Shows Organizations at Risk from Unsecured Usb Flash Drives; Usage is More than Double Corporate IT Expectations


    Data Files On Personal Flash Drives In The Workplace Include Customer Records, Financial Information, Business Plans And Source Code


    MILPITAS, CALIFORNIA, April 9, 2008 - SanDisk Corporation (NASDAQ:SNDK) today announced the results of a new study demonstrating the risks of unsecured USB flash drive usage within enterprise organizations. A survey of both corporate end users and corporate IT managers, commissioned by SanDisk, revealed that IT executives are unaware of the extent to which unsecured flash drives are brought into their organizations: 77 percent of corporate end users surveyed have used personal flash drives for work-related purposes. However, when asked to estimate what percentage of the workforce uses personal flash drives, corporate IT respondents said only 35 percent.

    Users revealed the data files most likely to be copied to a personal flash drives include customer records (25 percent), financial information (17 percent), business plans (15 percent), employee records (13 percent), marketing plans (13 percent), intellectual property (6 percent), and source code (6 percent).

    Survey data indicated the portability of USB flash drives represents a significant risk of data loss. Approximately one in ten (12 percent) of corporate end users reported finding a flash drive in a public place. Additionally, when asked to pick the three most likely actions they would take if they found a flash drive in a public place, 55 percent indicated they would view the data.

    "Most CIOs are aware that data leaks can result in identity theft, compromise of intellectual property, and loss of trade secrets, as well as significant PR and financial damage to organizations," said Gil Mildworth, Senior Director of Marketing for SanDisks Enterprise Division. "Our survey demonstrates that, while there is some awareness of potential risks involved with unsecured USB flash drives, corporate IT execs need more effective policies, education, and technology solutions in order to mitigate the risks. Only a top-down effort involving intelligent device management, data monitoring, and centralized policy enforcement will sufficiently reduce risks, while allowing organizations to reap the productivity benefits of enhanced mobility."

    Corporate Policies Largely Reactive; Knowledge Varies

    Survey results demonstrated that while some organizations have taken steps to implement policies and educate users about proper USB flash drive usage, their actions are primarily reactive. According to IT respondents, more than two-thirds (67 percent) are implementing or have implemented policies as a result of a data or security breach in their organization. Additionally, only slightly more than half (52 percent) of all of IT respondents have implemented an endpoint security solution.

    Awareness of corporate USB flash drive usage policies is varied among respondents. Twenty-three percent of end users are either not familiar at all with their organizations policies regarding flash drive usage, or are aware that they exist but arent familiar with specific details.

    At the same time, almost half (44 percent) of end users revealed that, to their knowledge, their organization does not have a policy that forbids copying corporate data on personal USB flash drives. Another 16 percent were not aware of an existing policy, while 40 percent reported their company does have a policy forbidding corporate data on personal flash drives.

    IT manager responses were consistent with end users. Twenty-one percent described their employees understanding of policies as only limited, while 33 percent were described as having moderate understanding, 28 percent reported as having good understanding, and 19 percent reported as having complete understanding. When asked about training, IT respondents reported that employees are trained either once per year on policies around USB flash drive usage (33 percent); that they are trained more than once per year (24 percent); that employees receive training only once when hired (22 percent); that they are trained only on an as-needed basis (17 percent); and that they never train employees (3 percent).

    More Education Required to Mitigate Risk, Potential Costs

    Some 41 percent of corporate IT managers report they are at least somewhat uncomfortable with the level of USB flash drive usage in their organization, revealing a significant level of potential risk. Corporate end users validated their concerns by reporting that one out of every five have little to no awareness about the risks involved with transporting corporate data on flash drives (21 percent), revealing a significant potential for data loss.

    About SanDisks USB Flash Drive Study

    SanDisks report on USB flash drive usage in the enterprise was a result of phone surveys, conducted in the U.S. in March 2008 by Applied Research-West for SanDisk, of both corporate end users and corporate IT managers. The goal of the surveys was to learn more about flash drive usage in the enterprise, as well as the awareness of potential risks involved with transporting corporate data on personal flash drives.

    SanDisk, a global leader in USB flash drives, is driving the convergence of secure portable storage, identity management and virtualization through its Enterprise Division to create a comprehensive solution for mobile professionals in enterprises and government agencies. Today, SanDisks Enterprise Division offers solutions for securely storing and managing enterprise data, within and outside the enterprise environment. With the upcoming introduction of virtualization and identity and management capabilities, SanDisk expects to allow IT managers to boost employee productivity by mobilizing the corporate computing environment through flexible, secure solutions that also reduce total cost of ownership.

    More information is available at www.sandisk.com/enterprise.


    2008-04-12

    SanDisk Announces Version 3.0 Of CMC Software, Offering New Features and Efficiency for Central Management of Secure USB Flash Drives


    CMC 3.0 Streamlines Configuration, Application Distribution And License Management For SanDisk Cruzer Enterprise Drives

    MILPITAS, CALIFORNIA, April 8, 2008 - SanDisk Corporation (NASDAQ:SNDK) today announced version 3.0 of its CMC (Central Management & Control) software for managing SanDisks secure Cruzer Enterprise USB flash drives.

    CMC transforms portable storage into a mobility and productivity asset by giving IT departments a powerful tool for lifecycle management of Cruzer Enterprise drives - including deployment throughout the organization, password recovery and renewal through the network, central back-up and restore, central usage tracking, and remote termination of lost drives.

    With version 3.0, CMC gains additional strength through new features that include:

    • Application distribution. CMC 3.0 allows central distribution of productivity applications to Cruzer Enterprise drives through the network, with new applications appearing in the Cruzer Enterprise launchpad, easily accessed through an icon in the system tray. This makes it possible to rapidly introduce new applications, without users having to initiate an installation process or having to bring their drives to the IT department.

    • License management. CMC now keeps track of application and seat licenses on Cruzer Enterprise drives. This reduces the burden of tracking software usage.

    • Streamlined deployment and user provisioning. Cruzer Enterprise drives can now be remotely configured from any corporate PC without requiring pre-installation of a software agent. This contributes to overall user productivity and shrinks the time and effort required to add new drives, especially in large organizations with multiple locations and many remote workers.

    • Expanded reports. IT administrators can create pre-defined reports on user activity, and have access to a wizard for creating dynamic reports on demand. This gives the IT department new tools for uncovering violations of the organizations data security policies, and for providing confirmation of regulatory compliance through an enhanced audit trail.

    • Improved password policy control. Passwords can now be set to expire after a number of days selected by the IT department. This increases security by reducing the risk of unauthorized users gaining access to longstanding passwords. CMC 3.0 also offers the option of synchronizing with Active Directory password policies.

    CMC 3.0 is expected to be available in the third quarter, with pricing provided on request to enterprise clients.

    "CMC is at the center of SanDisks mission to make flash memory the preferred solution for authentication, workspace virtualization and endpoint security," said Etti Berger, Product Marketing Manager for CMC in SanDisks Enterprise Division. "We recognize that IT departments arent interested in new technologies that place additional demands on their time - no matter how compelling in theory. So we focused on adding features to CMC 3.0 that reduce the effort required to manage secure flash drives and therefore allow easy enterprise-wide implementation."

    Cruzer Enterprise protects all files stored on the drive with advanced hardware-based 256-bit AES encryption and mandatory password protection. Data is doubly protected with Cruzer Enterprise and CMC - files are protected from unauthorized users if the drive is lost or stolen, and the backup feature of CMC makes it simple for the IT department to provision a new drive with the files from the missing drive.



    2008-04-12

    SanDisk Introduces Cruzer Enterprise Fips Edition, a USB Flash Drive Providing Government-Certified Security


    With FIPS 140-2 Level 2 Certification, Cruzer Enterprise FIPS Edition Meets The Needs Of Government Agencies And Highly Regulated Industries

    MILPITAS, CALIFORNIA, April 8, 2008 - SanDisk Corporation (NASDAQ:SNDK) today introduced Cruzer Enterprise FIPS Edition, a USB flash drive with security certified by the National Institute of Standards and Technology (NIST) of the United States through its Federal Information Processing Standard (FIPS) program.

    Many government agencies require FIPS certification for portable storage devices, as do some private-sector companies in highly regulated industries such as financial services and healthcare. Based on SanDisks secure Cruzer Enterprise flash drive, the new Cruzer Enterprise FIPS Edition has additional data protection features including:

    • A software self-test routine that automatically runs whenever the drive is powered up, to verify the drives cryptographic function is intact.
    • Physical protection for the drives internal security module to deter tampering.

    Cruzer Enterprise FIPS Edition has received FIPS 140-2 Level 2 certification, and has also received the equivalent certification from Canada’s CSEC (Communications Security Establishment Canada). The certification indicates that Cruzer Enterprise FIPS Edition has met NIST standards for design of the cryptographic module, for the strength of encryption algorithms, and for resistance to physical intrusion.

    "Flash drives are a convenient and cost-effective way for IT managers to help their workforces become more mobile and more productive, but only if the drives offer the appropriate level of security," said Doron Peri, Product Marketing Manager for the Cruzer Enterprise product line in SanDisks Enterprise Division. "With Cruzer Enterprise FIPS Edition, SanDisk can now meet the needs of organizations demanding the highest level of data protection."

    Cruzer Enterprise FIPS Edition also offers all the features of the widely deployed Cruzer Enterprise, including:

    • Mandatory password-protection and hardware-based 256-bit AES encryption for all files stored on the drive.
    • Encryption keys never leave the drive, so they are safe from hacking attempts aimed at the host PC.
    • "Plug & Play" functionality on any PC - unlike many other secure flash drives, which first require installation of supporting software on the host machine.
    • Premium performance, with read speed of 24 megabytes (MB) per second and write speed of 20 MB/sec1.
    • Complete lifecycle management through SanDisks CMC (Central Management & Control) server software. CMC provides password recovery and renewal through the network, remote termination of lost drives, central back-up and restore, and central usage tracking. This means data is not lost when a drive is lost, and IT administrators can provision a replacement flash drive with user files stored on the network.

    Cruzer Enterprise FIPS Edition is available for order now in four capacities: 1 gigabyte (GB)2 for a list price of $87, 2 GB for a list price of $144, 4GB for a list price of $217, and 8GB for a list price of $385.


    2008-04-12

    SanDisk Offers RSA SecurID Two-Factor Authentication Technology Stored in Secure USB Flash Drives, Managed by SanDisk CMC Software


    "Two-For-One" Solution Provides Integrated Secure Data Storage And Two-Factor Authentication Technology From RSA In SanDisk Cruzer Enterprise Flash Drives

    MILPITAS, CALIFORNIA, April 7, 2008 - SanDisk Corporation (NASDAQ:SNDK) today announced the ability to deploy, store and use RSA SecurID® software tokens from RSA, The Security Division of EMC, on SanDisk Cruzer Enterprise USB flash drives. Now available for order, this "two-for-one" solution gives users a single device for secure data storage and two-factor authentication, an alternative to carrying both a flash drive and a separate hardware authenticator.

    Cruzer Enterprise is managed by SanDisks CMC (Central Management & Control) server software, making it easy for IT managers to provision and monitor flash drives throughout their lifecycle. At the same time, Cruzer Enterprise flash drives that contain RSA SecurID software tokens provide two-factor authentication capabilities for remote and mobile network access - requiring something users have (the one-time passcode generated on the drive, used with or without a PIN) and something users know (the drives password).

    "This is an ideal solution for employees who need to travel light and yet be fully connected, as well as for IT departments concerned with data security and regulatory compliance challenges," said Roy Ramati, Vice President and General Manager of the Enterprise Division at SanDisk. "Adding RSA SecurID to our management and security solutions for the enterprise is a major step forward in our mission: providing IT professionals with tools to enhance employee productivity through mobility and remote connectivity."

    SanDisk has certified interoperability between Cruzer Enterprise Flash Drives and RSA SecurID technology through the RSA Secured Partner Program, which enables interoperability partners to embed RSA technology within their products and solutions. The RSA Secured program includes a formalized certification process that puts each product through a series of tests to ensure that the end-user is getting the maximum available benefits from an interoperable solution.

    "Two-factor authentication is no longer a one-size fits all solution, so we are working with SanDisk to optimize our joint customers deployments by balancing risk, cost and convenience and offering a broad choice of authentication mechanisms," said Sam Curry, Vice President of Product Management and Product Marketing, Identity and Access Assurance Group at RSA, the Security Division of EMC. "By leveraging a single device to support additional security capabilities, we are building the necessary confidence that corporate data is being accessed securely by customers, partners and employees."

    SanDisk Cruzer Enterprise flash drives protect all files with advanced hardware-based 256-bit AES encryption. Users are also required to create a complex password during the set-up process. The combination of encryption and password protection makes it extremely difficult for unauthorized users to access data if the drive is lost or stolen. Cruzer Enterprise - available in 1, 2, 4 and 8 gigabyte (GB)1 capacities - is also fast, with read speed of 24 megabytes (MB) per second and write speed of 20 MB/sec2.

    CMC server software provides lifecycle management for Cruzer Enterprise drives, including centralized provisioning of drives throughout the organization, password recovery and renewal through the network, central back-up and restore, central usage tracking, and remote termination of lost drives. This means data is not lost when a drive is lost, and IT administrators can provision a replacement flash drive with user files stored on the network.

    CMC is also capable of working with RSA Authentication Manager to remotely provision software token seeds and, if necessary, the RSA SecurID application itself to remote employees - reducing the cost of deployment.

    SanDisk Cruzer Enterprise drives with pre-installed RSA SecurID software tokens, as well as CMC software with a module to support RSA SecurID two-factor authentication, are available for order now from SanDisk and SanDisk-authorized resellers. Cruzer Enterprise drives can securely store RSA SecurID software token seeds, available for purchase and enablement from RSA or its channel partners, to generate one-time passwords directly from the drive.


    2008-04-12

    State of Washingtons Division of Child Support Selects SanDisk Secure Flash Drives and Management Software


    Confidential Financial And Legal Data Now Secured With SanDisk Cruzer Enterprise USB Flash Drives, Managed By SanDisk CMC Server Software

    MILPITAS, CALIFORNIA, February 25, 2008 - SanDisk Corporation (NASDAQ:SNDK) today announced that the State of Washingtons Division of Child Support has selected SanDisks Cruzer Enterprise secure USB flash drives and Central Management & Control (CMC) server software to protect highly confidential client data at its headquarters and in 10 field offices statewide.

    The Division of Child Support (DCS) administers state and federal child support laws, including the collection of child-support payments from non-custodial parents. DCS manages about 350,000 active child-support cases and collects about $700 million per year in child-support payments.

    "With the many recent reports of data loss and theft involving government agencies around the world, we are pleased to help DCS respond to security problems before they happen", said Roy Ramati, vice president and general manager of the Enterprise Division at SanDisk. DCS employees dont have to give up the convenience of carrying data on flash drives, while the divisions information technology (IT) staff knows that data is password-protected and encrypted - and that Cruzer Enterprise drives can be easily managed with CMC, even in field offices far from headquarters.

    DCS, part of the Washington State Department of Social and Health Services, gathers highly confidential information - including Internal Revenue Service tax returns, employer records, criminal histories and even U.S. State Department passport data - in pursuing its collection efforts. Protecting this data from unauthorized access and improper use is crucial.

    As one element of its data security strategy, DCS last month purchased 200 Cruzer Enterprise drives along with SanDisks CMC software for managing the complete lifecycle of those drives. The secure flash drives are being provided to unit supervisors, who manage collection teams in DCS field offices. The master CMC console for provisioning and managing the drives will be at DCS headquarters in Olympia, Wash., with sub-administrators in each DCS field office.

    Cruzer Enterprise protects all files stored on the drive with advanced hardware-based 256-bit AES encryption. Users are also required to create a complex password during the set-up process. The combination of encryption and password protection makes it extremely difficult for unauthorized users to access data if the drive is lost or stolen. Cruzer Enterprise is also fast, with read speed of 24 megabytes (MB) per second and write speed of 20 MB/sec1.

    CMC server software provides lifecycle management for Cruzer Enterprise drives, including password recovery and renewal through the network, remote termination of lost drives, central back-up and restore, and central usage tracking. This means data is not lost when a drive is lost, and IT administrators can provision a replacement flash drive with user files stored on the network.
    ControlGuard, a leading provider of enterprise-grade security solutions and a member of the SanDisk Enterprise Solutions Technology Alliance (SESTA), managed the sale of CMC to the Division of Child Support.

    "ControlGuard and SanDisk together offer powerful tools to convert USB flash drives from security threats into security assets," said David Raanan, chief marketing officer of ControlGuard. "We applaud the State of Washingtons Division of Child Support for showing true leadership in protecting confidential data."




    Page: 1



    Share |





    Sandisk Cruzer Enterprise | Cruzer Enterprise | Encrypted USB | Sandisk Enterprise FIPS Edition | CMC | Secure USB drive | Secure USB drives | Secure USB flash drive | Enterprise security | Secure mobility | Reactive Data Solutions | SESTA | Sandisk Distributors | Sandisk Worldwide | Sandisk USB | Storage Devices | Corporate USB Drives | Data Storage | Sandisk Technology | Secure USB Devices | Virus Protected USB | McAfee USB | Sandisk USB with McAfee security