Focus on Microsoft
Workstation Shutdown / Logoff Policy Aug 16 2006 02:23PM
kfoutts orenickcompanies com (4 replies)
RE: Workstation Shutdown / Logoff Policy Aug 16 2006 04:42PM
Thaddeus McNamara (tk coast-radio com) (1 replies)
RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 16 2006 07:18PM
Jamie Fullerton (Jamie Fullerton ndbt com) (2 replies)
Re: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 17 2006 03:55PM
Thor (Hammer of God) (thor hammerofgod com) (5 replies)
Re: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 18 2006 05:24AM
Greg Mulholland (gmulholland aanet com au)
RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 18 2006 03:26AM
BARRETT,WILL (BARRETW airproducts com)
RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 17 2006 07:46PM
Maloney, Michael (MMaloney middlesexcc edu)
RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 17 2006 06:19PM
Mike McMahon (Mike McMahon us wdsglobal com)
RE: Workstation Shutdown / Logoff Policy Aug 17 2006 06:16PM
William J Bova (wbova austin utexas edu)
RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 17 2006 02:55PM
Thompson, Scott (scott thompson orion-sys com) (1 replies)
RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 17 2006 07:13PM
Kirk Foutts (kfoutts orenickcompanies com) (3 replies)
Re: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 22 2006 05:17PM
Allan Seyberth (nullconnect gmail com)
RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 22 2006 01:12PM
Peter Eden (peter eden utoronto ca)
Re: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 22 2006 05:43AM
Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa pacbell net) (1 replies)
Whole disk encryption Aug 24 2006 04:47PM
Sarah (sfelske bgsu edu) (5 replies)
Re: Whole disk encryption Aug 25 2006 05:58AM
Johnny Wong (johnnywkm gmail com)
Whole disk encryption Aug 25 2006 02:41AM
andrew probert trusted-solutions com au
If you're worried about fragments of temporary files from office, explorer
cache, residual data in sectors when a file is deleted (but not
overwritten many times), and swap-file residual data, then you need disk
encryption at the sector level.

Not to mention current surveys like this:
http://news.com.com/Confidential+data+really+is+at+risk/2010-1029_3-6108
603.html?tag=html.alert

Vista has 'bitlocker':
http://www.apcstart.com/site/pschnackenburg/2006/08/1066/your-money-or-y
our-hard-drive-vistas-full-disk-encryption-benchmarked

There are products around such as: WinMagic, SecureGuard, TrueCrypt,
SecureStar, to name a few.

Some laptop vendors provide hardware option - Dell & HP, but I haven't
looked at enterprise capability.

[I am unaligned to products]

Most products sit below Windows / Linux and add moderate overhead to CPU a
few percent (if doing AES encryption). Don't know about I/O latency.
They can convert disks in-situ.

Standard backup utilities, through O/S continue to work.

Disk-level imaging tools, however, need special consideration.

They can work with passphrases, smartcards and USBkeys that operate pre-boot.

For enterprise use, the key considerations are:

* Recovery, Recovery, Recovery, Help Desk, Support, Auditability
* If user loses usbkey, smartcards or forgets passphrase, you need over-ride
* Encryption needs to extend to USBDrive and CD/RW - DVD/RW (some
products do this as part of same scheme)
* Multi-user login i.e. handle multiple keys
* Group users of USB keys i.e. workgroup crypto-keys
* Auditors - need to be able to break-the-glass - escrow / recovery
* Systems Support - ditto
* Multiple boot / Compartmented operating systems e.g. one environment for
uncontrolled surfing, and another boot image for corporate LAN?

You need a Key Escrow server, or ability to distribute sets of keys to
workstations. In enterprise environment you absolutely need audit / system
support keys in addition to normal (Deployment of sofware is also
consideration.)

If you're concerned about real pedigree of security, then you also need to
be looking for evidence of independant security accreditation such as
FIPS140-2, EAL4 etc.

Enjoy!!

Andrew Probert
Seurity Consultant (CISSP)
Trusted Solutions Pty Ltd
+61 419303705
Australia

------------------------------------------------------------------------
---
------------------------------------------------------------------------
---

[ reply ]
Re: Whole disk encryption Aug 25 2006 02:35AM
Dietrich Heusel (dietrich heusel de) (2 replies)
Re: Whole disk encryption Aug 25 2006 06:00PM
Saqib Ali (docbook xml gmail com) (1 replies)
Re: Whole disk encryption Aug 30 2006 04:22PM
Kurt Buff (kurt buff gmail com) (2 replies)
RE: Whole disk encryption Sep 01 2006 09:24PM
Seren Thompson (Seren Thompson colorado edu)
Re: Whole disk encryption Aug 30 2006 04:53PM
Saqib Ali (docbook xml gmail com)
Re: Whole disk encryption Aug 25 2006 01:05PM
Sarah (sfelske bgsu edu)
RE: Whole disk encryption Aug 24 2006 09:09PM
Greg Merideth (gmerideth uclnj com)
RE: Whole disk encryption Aug 24 2006 06:06PM
Erik Anderson (eanders pobox com) (3 replies)
RE: Whole disk encryption Aug 25 2006 03:24PM
Brad Judy (Brad Judy colorado edu) (1 replies)
Re: Whole disk encryption Aug 28 2006 02:30PM
chuck (chuck chuckherrin com) (2 replies)
Re: Whole disk encryption Aug 28 2006 07:58PM
arek chelmnet pl
Re: Whole disk encryption Aug 28 2006 07:54PM
Jason Thompson (securitux gmail com) (1 replies)
Re: Whole disk encryption Aug 29 2006 03:23PM
matthew patton (pattonme yahoo com) (3 replies)
RE: Whole disk encryption Sep 03 2006 03:23AM
Galin, Matt (THIP, Corp) (matt galin thehartford com)
RE: Whole disk encryption Aug 31 2006 11:37AM
Galin, Matt (THIP, Corp) (matt galin thehartford com)
RES: Whole disk encryption Aug 30 2006 01:40PM
Willian A. Rabelo (willian assolan com br)
RE: Whole disk encryption Aug 25 2006 12:37PM
Maloney, Michael (MMaloney middlesexcc edu)
Re: Whole disk encryption Aug 24 2006 08:48PM
Nathaniel Hall (nathaniel d hall gmail com)
Re: Workstation Shutdown / Logoff Policy Aug 16 2006 03:04PM
Sebastian {En3pY} Zdrojewski (en3py itvc net)
RE: Workstation Shutdown / Logoff Policy Aug 16 2006 02:51PM
Jenkins, Mark (mark jenkins hp com)
RE: Workstation Shutdown / Logoff Policy Aug 16 2006 02:51PM
Finehout, David (Contractor) (dfinehout nrlssc navy mil) (1 replies)
RE: Workstation Shutdown / Logoff Policy Aug 16 2006 09:32PM
McLennan, James GS12 USA USAIMA (james mclennan us army mil)


 

Privacy Statement
Copyright 2010, SecurityFocus