ReverentCreature Posted March 18, 2016 Posted March 18, 2016 Hi there, For a few years we have had DeviceLock in place to control devices connected to our computers. What do you use in your schools? Here DeviceLock whitelists our devices and prevents personal and third party devices such as memory sticks or phones from being connected.
ZeroHour Posted March 20, 2016 Posted March 20, 2016 I *thought* Sophos had a feature that did some of this but its hard to find anything quite as powerful as DeviceLock.
mbedford Posted March 21, 2016 Posted March 21, 2016 We use a GPO to only allow USB drives (including mass storage on phones) to have write access if they are encrypted with BitLocker. Would that be secure enough for you? It sounds like you are currently just allowing\disallowing based on a list of allowed devices/users. This would give you a similar solution but would require that the data that is transferred onto said device is also encrypted which given the amount of articles you read nowadays of people finding DVD\USB\Laptops on trains, cant be a bad thing. I'm reasonably sure the same GPO could be configured to entirely ban USB drives encrypted or not, but that falls a little too far in to the security side of the security VS usability equation for me. Mike
ReverentCreature Posted March 22, 2016 Author Posted March 22, 2016 (edited) That sounds like a good solution. Our staff currently use Integral Crypto memory sticks. What about cameras? Staff take a lot of photos on cameras and connect up their USB leads to get the photos off. Again we whitelist ours and block others. Which goes for USB flip video cameras USB microphones etc... Edited March 22, 2016 by ReverentCreature
Angy Posted March 29, 2016 Posted March 29, 2016 Whether you're searching for Device Control only or also Data Loss Prevention and Mobile Device Management, Endpoint Protector Device Control, Data Loss Prevention, MDM. Enterprise Solutions - Endpoint Protector can help you. It offers device whitelisting as well as encryption for USB devices and forces users to use only encrypted devices. 1
fiza Posted March 29, 2016 Posted March 29, 2016 We use a GPO to only allow USB drives (including mass storage on phones) to have write access if they are encrypted with BitLocker. Would that be secure enough for you? It sounds like you are currently just allowing\disallowing based on a list of allowed devices/users. This would give you a similar solution but would require that the data that is transferred onto said device is also encrypted which given the amount of articles you read nowadays of people finding DVD\USB\Laptops on trains, cant be a bad thing. I'm reasonably sure the same GPO could be configured to entirely ban USB drives encrypted or not, but that falls a little too far in to the security side of the security VS usability equation for me. Mike @mbedford How do you encrypt mass storage on phones? How does Bitlocker work when school cameras are connected via usb to transfer video that students have taken?
mbedford Posted April 1, 2016 Posted April 1, 2016 @mbedford How do you encrypt mass storage on phones? How does Bitlocker work when school cameras are connected via usb to transfer video that students have taken? Phones we don't have much demand for. The student machines are not part of this GPO and that is were the majority of phone storage usage comes from. We offer access to all of the major cloud storage providers though (Google\Microsoft\Dropbox....) so the demand for any USB storage is decreasing year on year. In regards to camera's, I dont think I was clear in my initial response. We prevent writing to non encrypted devices, read still works just fine. Mike
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now