tj2419 Posted November 24, 2017 Posted November 24, 2017 (edited) We are looking at improving our practices with encryption with the upcoming GDPR changes. What do you guys do with regards to staff/students and USB drives? Do you encrypt pen drives? Ban them? Or just let staff use them as normal? If you encrypt them do you have a way to block drives that aren't encrypted? For laptops i am guessing windows 10 bitlocker is the best way to go forward. Do you have this setup on just staff laptops? Or all computers? Thanks Edited November 24, 2017 by tj2419
Rob_D Posted November 24, 2017 Posted November 24, 2017 We're moving to block all USB drives in January, with Sophos device control polices. We will, however, be issuing encrypted memory sticks in exceptional circumstances. I think Sophos can be set to only block unencrypted devices, but we're going for the block everything with specific exceptions rout. And yeah, rolling out bitlocker drive encryption on any offsite laptops. 1
Passat1983ICTech Posted November 24, 2017 Posted November 24, 2017 we are go in to Encryption all us b driver and hard drives
tj2419 Posted November 24, 2017 Author Posted November 24, 2017 And yeah, rolling out bitlocker drive encryption on any offsite laptops. Are you planning on encrypting any onsite laptops or computers? Just thinking incase of a break in or something.
mthomas08 Posted November 24, 2017 Posted November 24, 2017 We are considering blocking USBs and only allowed on a per basis otherwise they will be encrypted. Users will be responsible for them. Laptops will be Bitlocker Windows 10 - gives us the chance to stick W10/SSDs in them.
Rob_D Posted November 24, 2017 Posted November 24, 2017 Are you planning on encrypting any onsite laptops or computers? Just thinking incase of a break in or something. As "onsite laptops" are shared pupil use ones, having an extra level of authentication would cause a fair bit of hassle and be time consuming for someone. Much the same excuse for desktops. We get enough complaints when the wake-on-lan doesn't work for desktops, imagine how much kickback we'd get if they had to punch in a password and wait for it finish booting before logging on. Add to that the fact that all onside machines are domain joined with no user data being saved to the local drives and bitlockering them is more trouble than its worth.
enjay Posted November 24, 2017 Posted November 24, 2017 Add to that the fact that all onside machines are domain joined with no user data being saved to the local drives and bitlockering them is more trouble than its worth. Your servers, however, are probably worth encrypting on that logic. Does anyone here have encrypted servers?? We've got Google Drive, so have told staff to either use Drive or password-protect documents if they need to be on a memory stick. To be honest, since getting Drive, we see very few memory sticks in use.
jthompson Posted November 24, 2017 Posted November 24, 2017 We BitLocker all staff PCs (desktops and laptops) in case of loss/theft but haven't tackled the USB drive issue yet. Student laptops and desktops, we don't generally bother as there's no pressing need to. We've always discouraged the use of USBs, however. In most cases, the USBs are used to transfer files to/from a home computer, and are often a fall-back option when something is too large to email, etc. Having tighter restrictions may just create annoyance and push users towards private Dropbox accounts, etc. which I'd rather avoid.
mikkydoos Posted November 24, 2017 Posted November 24, 2017 (edited) Banned via GPO here for everyone except on public area computers. Outside access is via vpn/rdp. And a staff signed statement stating no data will be uploaded / shared etc. Edited November 24, 2017 by mikkydoos
Ditto Posted November 24, 2017 Posted November 24, 2017 We've recently banned, but it has caused some grumbles. However, it sometimes throws up a training need. The main grumble has been around scanning images to USB sticks. Solution: educate how to 'scan to email'. Oh - and then make sure all our scanning devices that are supposed to support that actually do! We might soften the ban for a small number of cases if a need is proved, but in that case I's support encryption.
GuyJD Posted November 24, 2017 Posted November 24, 2017 Your servers, however, are probably worth encrypting on that logic. Does anyone here have encrypted servers??I'm in the process of encrypting my servers, my on-site laptops/desktops don't allow saving locally so I'm no encrypting those.
GrumbleDook Posted November 24, 2017 Posted November 24, 2017 Can I just point out that this is not a GDPR thing, but is actually to do with DPA98? No? I’ll get my coat then. 3
3s-gtech Posted November 24, 2017 Posted November 24, 2017 Unencrypted are banned for staff, by policy. I provide Kingston Datatraveler Locker+ G3 drives for staff that want them. I haven't started blocking unencrypted drives by GPO, but I am one violation from doing so!
ReverentCreature Posted November 28, 2017 Posted November 28, 2017 In my last job I purchased DeviceLock which was group policy based and whitelisted the schools devices. All personal USB sticks, phones, cameras were blocked. Here I do the same thing using the schools Sophos antivirus software. I suggest you find out if your AV software has this functionality. its increasingly popular. Block individual devices or the make and model. All staff here now have to use our purchased encrypted memory sticks. As mentioned this should have been done years ago as required under the Data Protection Act!
enjay Posted November 28, 2017 Posted November 28, 2017 As mentioned this should have been done years ago as required under the Data Protection Act! Well, not exactly - DPA doesn't say you must use encrypted memory sticks, it says you must protect the data. Policy saying "don't do it" or "if you must do it, password-protect it" is okay. Use of a non-encrypted memory stick with no PII stored on it is fine.
thimon Posted November 28, 2017 Posted November 28, 2017 We allow all usb devices to be read normally, however if the user wants to write any data to it they need to encrypt it with Safend. 1
ReverentCreature Posted November 28, 2017 Posted November 28, 2017 Use of a non-encrypted memory stick with no PII stored on it is fine. True I guess but you cant rely on every user to remember or follow the policy and it only takes on slip-up to get in trouble. So to me it makes sense not to give them the opportunity to slip up in the first place. Its one less thing that can go wrong if you just don't allow unprotected sticks in the first place.
GrumbleDook Posted November 28, 2017 Posted November 28, 2017 True I guess but you cant rely on every user to remember or follow the policy and it only takes on slip-up to get in trouble. So to me it makes sense not to give them the opportunity to slip up in the first place. Its one less thing that can go wrong if you just don't allow unprotected sticks in the first place. And this is why Data Protection is an exercise in Risk Management ... and we shouldn't expect everything to be black and white.
Zoom7000 Posted November 28, 2017 Posted November 28, 2017 I've verbally (and banned in the ICT AUP) all USB Flash Drives. I was planning to apply a physical ban by installing USBDLM, assigning K, L, M, N, O to USB Flash Drives and then blocking these drives via GPO. Unless someone can advise on a better method.
enjay Posted November 28, 2017 Posted November 28, 2017 True I guess but you cant rely on every user to remember or follow the policy and it only takes on slip-up to get in trouble. So to me it makes sense not to give them the opportunity to slip up in the first place. Its one less thing that can go wrong if you just don't allow unprotected sticks in the first place. By that measure, I'm assuming you don't have any printers in case someone prints out something sensitive. Or email in case they email something sensitive. Or an Internet connection in case they upload something sensitive.
MrFrostmaul Posted November 28, 2017 Posted November 28, 2017 Ban on all with ESET Device Control, apart from our photography computers for SD Cards etc. and certain USB's allowed for some staff. Laptops are encrypted with BitLocker and overall the USB ban was okay as we say use OneDrive and they don't really have an excuse.
kennysarmy Posted March 9, 2018 Posted March 9, 2018 We run Sophos End Point Protection with InterceptX Does anyone know if it's possible to restrict USB memory sticks to only those that are encrypted? I can't seem to see how to do it if it's possible...
Rob_D Posted March 9, 2018 Posted March 9, 2018 We run Sophos End Point Protection with InterceptX Does anyone know if it's possible to restrict USB memory sticks to only those that are encrypted? I can't seem to see how to do it if it's possible... In sophos endpoint, device control policies can differentiate between normal and encrypted usb sticks.
kennysarmy Posted March 9, 2018 Posted March 9, 2018 In sophos endpoint, device control policies can differentiate between normal and encrypted usb sticks. [ATTACH=CONFIG]48004[/ATTACH] Thanks I've found it! This seems to be applicable to the various "groups" I've set up of PC's on cloud central. So I could ban all non secure memory sticks for all staff PC's... Is there a way to link Sophos Central to our AD so we can do policies on our security groups?
Rob_D Posted March 9, 2018 Posted March 9, 2018 As I understand it, the sophos device control policies are machine policies. We have the enterprise console on a local server that links to AD, but it only allows us to sync computer OUs to Sophos groups. It sounds like you have a slightly different setup, so you might have more user based options than us though.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now