Guaranteeing Data Sanitization Across the Data Lifecycle for a Vietnamese State-Owned Bank | Blancco Case Study

As cybersecurity becomes a larger concern across the globe, organizations are expected to make compliance with legislation a priority. In Vietnam, a new cybersecurity law went into effect in January 2019, and many other global regulations are being enacted throughout the globe. PCI DSS, in particular, is a major part of global compliance for any global finance organization. Data sanitization, or the process of deliberately, permanently and irreversibly removing or destroying the data stored on a memory device to make it unrecoverable, is an important part of both expanding an organization’s endpoint security in active data environments and decreasing the impact of a potential data breach at end-of-life.

Challenge

VietinBank needed a data sanitization solution to support its data security operations and ensure full data security throughout the data lifecycle. As a result, the company could ensure all customers data is well protected at all points of this lifecycle. Often, storage media got broken and needed to be sent back to the provider for maintenance/warranty purposes. This left the potential for data on this device to be stolen or used illegally.

Previous processes for erasure were typically done through manual wiping or physical destruction such as pressing, hammering or dumping random data to the hard disk. The process was very manual and risky, as there was a substantial chance of human error from the responsible person or department. Additionally, it was costly and presented a higher risk of data breach. VietinBank needed a more efficient solution that could securely remove data quickly and permanently, while also guaranteeing a full audit trail for compliance—ensuring the financial firm could achieve compliance with the data sanitization requirements outlined in PCI DSS.

Solution

VietinBank purchased the full suite of Blancco data erasure solutions, including both software and hardware solutions. To erase HDDs and SSDs in laptops, desktops and servers, VietinBank uses Blancco Drive Eraser. To permanently erase files and folders in Windows and Linux environments, the company uses Blancco File Eraser. For active erasure, VietinBank has invested in Blancco Virtual Machine Eraser for virtual machine erasure and Blancco LUN Eraser for LUN erasure (mapping from SAN or Local Disk). Additionally, the company has chosen Mobile Diagnostics & Erasure for mobile phone erasure. For hardware: the Array Server Eraser for HDD and SSD erasure and the Ontrack Eraser® Degausser machine for physically broken HDDs and tapes.

VietinBank has been using these solutions to address all possible security threats that can be mitigated with secure data erasure and to comply with national regulations (State Bank of Vietnam, Vietnam Cyber Law) and global regulations, such as PCI DSS.

“VietinBank purchased Blancco’s Data Erasure Management solution to support our internal data security policies and mitigate the risks of a data breach. Blancco helped VietinBank accomplish the project quickly and conveniently and provides erasure with a full auditable process via Management Console, enabling efficient management and tracking. We are looking forward to seeing even more improvements from Blancco so that we can cooperate long into the future.”

Nguyen The Thinh – Deputy Director, Information Technology Center

About VietinBank

Established in 1988 and headquartered in Hanoi, Vietnam Joint Stock Commercial Bank for Industry and Trade (VietinBank) is a leading financial and banking group that plays a key role in Vietnam’s financial and banking system. The company has 155 local branches in Vietnam and 958 transaction offices throughout the country’s regions and provinces. VietinBank has also established a large correspondent banking network with more than 1,000 banks in 90 countries and territories across the globe. Learn more at https://investor.vietinbank.vn.

About Blancco

Blancco is the industry standard in data erasure and mobile device diagnostics. Blancco data erasure solutions provide thousands of organizations with the tools they need to add an additional layer of security to their endpoint security policies through secure erasure of IT assets. All erasures are verified and certified through a tamper-proof audit trail.

Blancco data erasure solutions have been tested, certified, approved and recommended by 15+ governing bodies and leading organizations around the world. No other data erasure software can boast this level of compliance with the rigorous requirements set by government agencies, legal authorities and independent testing laboratories.