Secure file exchange management critical to successful transfers

 

Summary

Moving large files to external parties proves a tricky task as there are no clear best practices. Identifying the best solution starts with determining requirements.

Events

Social Media World Forum
22 - 23 Sep 2010

Suntec, Singapore

Governmentware 2010
28 - 30 Sep 2010

Suntec, Singapore

The 5th Annual CIO Forum Asia
28 Sep 2010

Singapore

IDC's Asia/Pacific Cloud Computing Conference 2010
31 Aug 2010

Marriott Hotel, Singapore

In an earlier post about secure file exchanges, many TechRepublic members came back with a mixed bag of opinions on the topic.

TechRepublic member flhtc and darksidegeek outline how they have invested time and effort into crafting a homegrown solution of sorts based on scripting, front-end interfaces and URL obfuscation. While they will definitely get points for software purchase cost control, there are questions of how well these services will scale and how friendly the interface is for users who are not IT pros.

Smaller shops may be able to craft solutions that work well for the occasional large file transfer. On the opposite side of this, if a large enterprise has a Web development team available internally, this type of of solution could be made with a high degree of quality instead of a collection of scripts copied and pasted off of the Internet. Also in the post, TechRepublic member Jason_Mcc sums up my perspective well. Quoting Jason:

There is no shortage of tools or various ways of accomplishing this task, if your users are sufficiently capable or you are just doing it yourself.

My point is that the technology is available. Most solutions, large or small, will involve an SSL-encrypted session or enhanced FTP service like SFTP. But the root problem is management of these services. My stance is that I am a fan of self-service for all skill levels. So, for the marketing employee who needs to get a 2 GB-compressed file to the advertisement agency every day for the next few weeks as new company commercials are edited and produced, a one-timer IT service can get old very quickly.

Various IT operations will have a wide range of secure file transfer requirements. Topics such as file types, restricted content, bandwidth usage, cost, access control, delegation, storage requirements, backup requirements, and other factors are a starting point for determining the best way to approach a solution. Smaller shops may be able to stand up a small Web server with externally facing access and manage one-at-a-time large transfers.

Larger enterprises will spend more time identifying the requirements and management policies so that the solution becomes a user-friendly tool. That is important, because if the mechanism is not user friendly, users will find another way to transfer content. This can include costly or insecure mechanisms.

What, then, is the nirvana of large, secure file transfer? It would be a service that meets the following requirements:

  • Is easy to use for non-IT employees as a tool that is part of their job
  • No involvement of IT, except for installation, upgrades, and policy definition
  • Is easily accessible for external parties from an invitation from authorized internal person
  • Has robust logging of transfer and access of content
  • Active Directory integration
  • Application and storage both hosted internally
  • Policy and delegation for management
  • Compliance requirements maintained

Ideally, IT would use a solution that would be internally administered and provided like other "commodity" items such as e-mail and Web access. The requirements listed above is my short list of requirements for a secure file exchange implementation.

In my initial research, I had pointed out four commercial solutions that can provide solutions for this need. I am inclined to look first at the Accellion Managed File Transfer for an enterprise solution. Remember that everyone's needs may vary, and the use case for large, external file transfer may vary widely from organization to organization. What have you done to identify your requirements for secure file transfer? Share your comments below on what you have learned along the way.

Rick Vanover is a systems administrator for Safelite AutoGlass in Columbus, Ohio. Rick has over 12 years IT experience and focuses on virtualization, Windows-based server administration, and system hardware.

Talkback

Many options available!

Hi Rick. Good article, its something that as specialist in a range of file transfer solutions at Pro2col we deal with on a day to day basis. As you point out each business has its own unique set of requirements but the general feature list remains the same. Depending upon budget there are plenty of options for customers it also depends on how they want to move data - by this I mean does a customer want to share data via email based solutions which require manual interaction or do they want the solution to form part of an automated workflow. Accellion is a great solution but only covers the manual process of sending files and is considered to be at the top end of the price range. Other options include Files2Links for a mid-range priced product with solid feature set or Hermstedt StingRay for the a slightly different feature set. I mention these two as they weren't in your original piece and they are products I've sold in the past. I've seen a number of companies develop their own solutions in the past which invariably come in late, over budget and have major support impacts going forward for the business. Personally, and I appreciate as a company I'm going to have a slightly biased opion here but I can't understand why any Enterprise would develop their own solution when more or less every angle is covered in the marketplace - if you know where to look. Cheers. James

James Lewis May 15th, 2009 Reply

RE: Many options available!

Not sure if you allow links but thought your readers might like them anyway:
http://www.files2links.com
http://www.hermstedtstingray.com
http://www.pro2col.com
Cheers

James Lewis May 15th, 2009 Reply

RE: RE: Many options available!

James, interesting toughts. Haveoyu everheard of a product out ofAustralia called i-BAHN?
http://www.remasys.com/ibahn.php

Anonymous June 1st, 2009 Reply
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
HP Data Protector delivers high-performance data protection at up to 70% lower TCO.
Tech Vendor: HP
Did you know?
Did you know?

ZDNet Asia Live

Iwebslog.com-Multi-task tricks of the Table Move handle in Word: Click or double-click the Table Move handle... http://dlvr.it/4xkZW #Excel

34 minutes ago by learnexcel on topsy

Microsoft aiming to hone CRM pitch: As it gears up to start testing a new version of its product, Redmond says it'... http://bit.ly/cCRyE6

10 things you should know about NoSQL databases: The relational database model has prevailed for deca... http://bit.ly/9kJeXc - #Asia #News

Multi-task tricks of the Table Move handle in Word: Click or double-click the Table Move handle to qu... http://bit.ly/b7UBPf - #Asia #News

Microsoft aiming to hone CRM pitch: SAN FRANCISCO--Microsoft is tired of seeing Salesforce.com get all the headlin... http://bit.ly/d6Uf6U

Microsoft aiming to hone CRM pitch: SAN FRANCISCO--Microsoft is tired of seeing Salesforce.com get all the headlin... http://bit.ly/9vsZxf

who would've thunk it?? increasingly important medium.. 'S'pore: Social media trumps paid keyword ads' - ZDNet Asia - http://bit.ly/axe88O

RT @zdnetasia: Oracle's Hurd for Phillips swap: What's the customer relations impact? http://ur1.ca/1jqms

Salesforce chief: Enterprise tech lacks innovation: Consumer tech makers such as Twitter are setting ... http://bit.ly/ca4KYi - #Asia #News

Adobe warns of zero-day hole in Reader, Acrobat: Critical vulnerability could allow an attacker to ta... http://bit.ly/bY9Xe6 - #Asia #News

Microsoft aiming to hone CRM pitch http://bit.ly/aXa9nj | #Droid #Android

Microsoft aiming to hone CRM pitch http://bit.ly/dn8jno

3 hours 32 minutes ago by superstarch on topsy

Study: Two-thirds of Web surfers fall prey to online crime: Survey finds China, Brazil, India, and th... http://bit.ly/bGk6N2 - #Asia #News

Link to the Dual Roles of the CIO: http://www.ciodashboard.com/cio-careers/cio-dual-roles/

12 hours 45 minutes ago by cbcurran on Boeing CIO: IT key to drive business growth

Here's another view of the dual roles of the CIO that I think is consistent. What we've found, however, is that only about 1 in 4 CIOs o...

12 hours 46 minutes ago by cbcurran on Boeing CIO: IT key to drive business growth

I agree with the author's sentiment in that Oracle seems to be set on a course to building an anti-open-source reputation. I don't agree ...

13 hours 50 minutes ago by sisto on Could Oracle fracture open source community?

Hi Rick, I like your point that there is a time and a place for automation, and that it can be quite effective when used properly. One su...

16 hours 10 minutes ago by XebiaLabs on Agile drivers for new project management tools

sorry for the double entry just a mistake

19 hours 21 minutes ago by notek on 5 ways to avoid removable media malware

Amazing and very informative blog one point i'd like to point out is that, for number 2 instead of completely restraining the use of remo...

19 hours 22 minutes ago by notek on 5 ways to avoid removable media malware

S'pore: Social media trumps paid keyword ads http://bit.ly/9Z7dNd

19 hours 39 minutes ago by lenwilton on topsy

Hi. My name is Philippe de Passorio, head of Total Immersion office in Apac. Since we have opened our subsidiary in Hong Kong 1 year ago,...

20 hours 25 minutes ago by philippe on APAC lags in augmented reality adoption

Haha, thought long and hard about how to phrase it... no worries, you owe me lunch then, ;)

23 hours 25 minutes ago by yedwin on Is M'sia's online world ready for free speech?

Nice post man. Looks like I don't have to write one on this now.

23 hours 47 minutes ago by davidlian on Is M'sia's online world ready for free speech?

The only reason Oracle has a leg to stand on here is that Sun didn't open source all of Java. The saw that Java as a desktop application...

1 day 29 minutes ago by txtechdog on Could Oracle fracture open source community?

I recently made some good experiences with CopyRight2 from Sys-Manage. You can download a trial version here: http://www.sys-manage.com/P...

1 day 7 minutes ago by JPatrick on Migrate shares from one Windows NT server to another

I have to disagree with the author's statement "If Oracle destroys OpenOffice and MySQL the Linux operating system would be left with, wh...

1 day 28 minutes ago by schumacr on Could Oracle fracture open source community?

Oracle may well kill OpenOffice and MySQL but the FOSS community has a better DB in PostgreSQL, and OOo will be forked to get out from un...

1 day 56 minutes ago by GreyGeek on Could Oracle fracture open source community?

sir want create my own accounting software but i dont know anythink abount the programing i try to improave my self with learn of some ex...

1 day 28 minutes ago by parveenidhi on Create a shortcut to a custom Word template