Jump to content

Recommended Posts

Posted (edited)

And if not how can you prove that what you do is secure?

 

At the moment we do, purely because we had an SQL server running on staff laptops with student assessment data. That is now being sent the way of the dinosaur.

 

Now I've been thinking that if:

 

1) All local profile directories are re-directed to their Home drive (Desktop, Downloads, Documents etc.)

2) They can't change those locations, and remove admin access to their user accounts and make them power users so they can install software, but nothing else

3) Encrypt offline files (already done)

4) 90% of the time staff at home use VPN to connect back to the network so

4a) We could remove offline files entirely and have staff only use VPN and only access files physically on our servers over a secure link

 

Then if someone gets hold of their laptop they'd be unable to decrypt the encrypted offline files, so the data is secure. If the user left the laptop logged on and unlocked - well that's exactly the same if it's encrypted or not.

 

Is there a hole somewhere I can't see between not being able to access the whole disc (with no student files stored outside of encrypted offline) and accessing the disc but not being able to logon and decrypt offline files.

 

If I remember correctly all NTFS-Account tools can only change the password on local accounts - and a local admin account still can't decrypt those files.

 

If all this is true, how can it be proved to Ofsted that it is safe when the holy grail at the moment is to encrypt everything?

Edited by Trapper
Posted
I believe the requirement is from the ICO. If a laptop gets stolen your organisation gets fined. You are supposed to use FIPs 140-2 compliant encryption. You still get fined if some data gets out but less. I think a lot of places use truecrypt but its not FIPs compliant. If the user can write data to the laptop, even the internet cache you have the potential for data leakage if someone got hold of the laptop. I think that's the justification for full disk encryption.
Posted
We encrypt school-owned staff laptops with bitlocker or filevault. We don't have any policies on staff owned devices or force any mobile device policies
Posted (edited)
If the user can write data to the laptop, even the internet cache you have the potential for data leakage if someone got hold of the laptop.

^ We use BitLocker on all school-owned laptops for exactly this reason.

Edited by Arthur
Posted

bitlocker is good if you have windows enterprise licences - you can use a usb stick if the laptop does not have a tpm chip.

Recovery keys are stored in active directory which makes things easier.

Posted

Another vote for bitlocker here

All staff have USB keys that have been crippled to 1mb (I think) that they must insert into the laptop before it is powered on otherwise it won't boot. All recovery keys are stored with the machine account in AD

Posted
Another vote for BitLocker, as an aside are you guys just using the TPM \ USB or do you lock down with a startup PIN as well?
  • 1 month later...
Posted
Bitlocker with recovery key in ad. Staff who work with confidential info are given fips certified biometric usb drives. Staff use vpn from home what limits need for external storage
Posted
Are there any guides for encrypting devices with Bitlocker? It sounds good, I just don't want to bugger anything up in the process of trying to set it up!

 

We do the bitlocker during the mdt deployment when the device is originally built. This also puts the key in AD

Posted
As an aside are these laptops domain joined? I like the sound of the new Azure AD join method using the O365 account for roaming devices as I wonder if the user experience off domain could be a bit hit and miss (cached passwords, GPOs etc)
Posted
All laptops purchased have TPM chips the past few years, and they're all setup with bitlocker + the key is stored in AD. SCCM does all the fancy business during imaging.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...