|
Focus on Microsoft
Workstation Shutdown / Logoff Policy Aug 16 2006 02:23PM kfoutts orenickcompanies com (4 replies) RE: Workstation Shutdown / Logoff Policy Aug 16 2006 04:42PM Thaddeus McNamara (tk coast-radio com) (1 replies) RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 16 2006 07:18PM Jamie Fullerton (Jamie Fullerton ndbt com) (2 replies) Re: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 17 2006 03:55PM Thor (Hammer of God) (thor hammerofgod com) (5 replies) Re: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 18 2006 05:24AM Greg Mulholland (gmulholland aanet com au) RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 18 2006 03:26AM BARRETT,WILL (BARRETW airproducts com) RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 17 2006 07:46PM Maloney, Michael (MMaloney middlesexcc edu) RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 17 2006 06:19PM Mike McMahon (Mike McMahon us wdsglobal com) RE: Workstation Shutdown / Logoff Policy Aug 17 2006 06:16PM William J Bova (wbova austin utexas edu) RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 17 2006 02:55PM Thompson, Scott (scott thompson orion-sys com) (1 replies) RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 17 2006 07:13PM Kirk Foutts (kfoutts orenickcompanies com) (3 replies) Re: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 22 2006 05:17PM Allan Seyberth (nullconnect gmail com) RE: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 22 2006 01:12PM Peter Eden (peter eden utoronto ca) Re: Workstation Shutdown / Logoff Policy :VSMail mx1 Aug 22 2006 05:43AM Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa pacbell net) (1 replies) Whole disk encryption Aug 24 2006 04:47PM Sarah (sfelske bgsu edu) (5 replies) Re: Whole disk encryption Aug 25 2006 02:35AM Dietrich Heusel (dietrich heusel de) (2 replies) Re: Whole disk encryption Aug 25 2006 06:00PM Saqib Ali (docbook xml gmail com) (1 replies) RE: Whole disk encryption Aug 24 2006 06:06PM Erik Anderson (eanders pobox com) (3 replies) RE: Whole disk encryption Aug 25 2006 03:24PM Brad Judy (Brad Judy colorado edu) (1 replies) Re: Whole disk encryption Aug 28 2006 02:30PM chuck (chuck chuckherrin com) (2 replies) Re: Whole disk encryption Aug 28 2006 07:54PM Jason Thompson (securitux gmail com) (1 replies) Re: Workstation Shutdown / Logoff Policy Aug 16 2006 03:04PM Sebastian {En3pY} Zdrojewski (en3py itvc net) RE: Workstation Shutdown / Logoff Policy Aug 16 2006 02:51PM Finehout, David (Contractor) (dfinehout nrlssc navy mil) (1 replies) RE: Workstation Shutdown / Logoff Policy Aug 16 2006 09:32PM McLennan, James GS12 USA USAIMA (james mclennan us army mil) |
|
|
Privacy Statement |
cache, residual data in sectors when a file is deleted (but not
overwritten many times), and swap-file residual data, then you need disk
encryption at the sector level.
Not to mention current surveys like this:
http://news.com.com/Confidential+data+really+is+at+risk/2010-1029_3-6108
603.html?tag=html.alert
Vista has 'bitlocker':
http://www.apcstart.com/site/pschnackenburg/2006/08/1066/your-money-or-y
our-hard-drive-vistas-full-disk-encryption-benchmarked
There are products around such as: WinMagic, SecureGuard, TrueCrypt,
SecureStar, to name a few.
Some laptop vendors provide hardware option - Dell & HP, but I haven't
looked at enterprise capability.
[I am unaligned to products]
Most products sit below Windows / Linux and add moderate overhead to CPU a
few percent (if doing AES encryption). Don't know about I/O latency.
They can convert disks in-situ.
Standard backup utilities, through O/S continue to work.
Disk-level imaging tools, however, need special consideration.
They can work with passphrases, smartcards and USBkeys that operate pre-boot.
For enterprise use, the key considerations are:
* Recovery, Recovery, Recovery, Help Desk, Support, Auditability
* If user loses usbkey, smartcards or forgets passphrase, you need over-ride
* Encryption needs to extend to USBDrive and CD/RW - DVD/RW (some
products do this as part of same scheme)
* Multi-user login i.e. handle multiple keys
* Group users of USB keys i.e. workgroup crypto-keys
* Auditors - need to be able to break-the-glass - escrow / recovery
* Systems Support - ditto
* Multiple boot / Compartmented operating systems e.g. one environment for
uncontrolled surfing, and another boot image for corporate LAN?
You need a Key Escrow server, or ability to distribute sets of keys to
workstations. In enterprise environment you absolutely need audit / system
support keys in addition to normal (Deployment of sofware is also
consideration.)
If you're concerned about real pedigree of security, then you also need to
be looking for evidence of independant security accreditation such as
FIPS140-2, EAL4 etc.
Enjoy!!
Andrew Probert
Seurity Consultant (CISSP)
Trusted Solutions Pty Ltd
+61 419303705
Australia
------------------------------------------------------------------------
---
------------------------------------------------------------------------
---
[ reply ]