Trapper Posted August 5, 2015 Posted August 5, 2015 (edited) And if not how can you prove that what you do is secure? At the moment we do, purely because we had an SQL server running on staff laptops with student assessment data. That is now being sent the way of the dinosaur. Now I've been thinking that if: 1) All local profile directories are re-directed to their Home drive (Desktop, Downloads, Documents etc.) 2) They can't change those locations, and remove admin access to their user accounts and make them power users so they can install software, but nothing else 3) Encrypt offline files (already done) 4) 90% of the time staff at home use VPN to connect back to the network so 4a) We could remove offline files entirely and have staff only use VPN and only access files physically on our servers over a secure link Then if someone gets hold of their laptop they'd be unable to decrypt the encrypted offline files, so the data is secure. If the user left the laptop logged on and unlocked - well that's exactly the same if it's encrypted or not. Is there a hole somewhere I can't see between not being able to access the whole disc (with no student files stored outside of encrypted offline) and accessing the disc but not being able to logon and decrypt offline files. If I remember correctly all NTFS-Account tools can only change the password on local accounts - and a local admin account still can't decrypt those files. If all this is true, how can it be proved to Ofsted that it is safe when the holy grail at the moment is to encrypt everything? Edited August 5, 2015 by Trapper
free780 Posted August 5, 2015 Posted August 5, 2015 I believe the requirement is from the ICO. If a laptop gets stolen your organisation gets fined. You are supposed to use FIPs 140-2 compliant encryption. You still get fined if some data gets out but less. I think a lot of places use truecrypt but its not FIPs compliant. If the user can write data to the laptop, even the internet cache you have the potential for data leakage if someone got hold of the laptop. I think that's the justification for full disk encryption.
Sagima Posted August 5, 2015 Posted August 5, 2015 We encrypt school-owned staff laptops with bitlocker or filevault. We don't have any policies on staff owned devices or force any mobile device policies
Arthur Posted August 5, 2015 Posted August 5, 2015 (edited) If the user can write data to the laptop, even the internet cache you have the potential for data leakage if someone got hold of the laptop. ^ We use BitLocker on all school-owned laptops for exactly this reason. Edited August 5, 2015 by Arthur
maark Posted August 5, 2015 Posted August 5, 2015 bitlocker is good if you have windows enterprise licences - you can use a usb stick if the laptop does not have a tpm chip. Recovery keys are stored in active directory which makes things easier.
jamin100 Posted August 5, 2015 Posted August 5, 2015 Another vote for bitlocker here All staff have USB keys that have been crippled to 1mb (I think) that they must insert into the laptop before it is powered on otherwise it won't boot. All recovery keys are stored with the machine account in AD
gshaw Posted August 5, 2015 Posted August 5, 2015 Another vote for BitLocker, as an aside are you guys just using the TPM \ USB or do you lock down with a startup PIN as well?
IWDave Posted August 5, 2015 Posted August 5, 2015 Yes, we encrypt them with Sophos Endpoint Encryption.
jamin100 Posted August 5, 2015 Posted August 5, 2015 Another vote for BitLocker, as an aside are you guys just using the TPM \ USB or do you lock down with a startup PIN as well? Just the USB for us
Techie2000 Posted September 13, 2015 Posted September 13, 2015 Are there any guides for encrypting devices with Bitlocker? It sounds good, I just don't want to bugger anything up in the process of trying to set it up!
rrrrr Posted September 13, 2015 Posted September 13, 2015 Bitlocker with recovery key in ad. Staff who work with confidential info are given fips certified biometric usb drives. Staff use vpn from home what limits need for external storage
rrrrr Posted September 13, 2015 Posted September 13, 2015 Are there any guides for encrypting devices with Bitlocker? It sounds good, I just don't want to bugger anything up in the process of trying to set it up! We do the bitlocker during the mdt deployment when the device is originally built. This also puts the key in AD
Techie2000 Posted September 13, 2015 Posted September 13, 2015 Is it also possible to do this with WDS?
gshaw Posted September 13, 2015 Posted September 13, 2015 As an aside are these laptops domain joined? I like the sound of the new Azure AD join method using the O365 account for roaming devices as I wonder if the user experience off domain could be a bit hit and miss (cached passwords, GPOs etc)
mrbios Posted September 13, 2015 Posted September 13, 2015 All laptops purchased have TPM chips the past few years, and they're all setup with bitlocker + the key is stored in AD. SCCM does all the fancy business during imaging.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now