Jump to content

Recommended Posts

Posted (edited)

We are looking at improving our practices with encryption with the upcoming GDPR changes.

 

What do you guys do with regards to staff/students and USB drives?

 

Do you encrypt pen drives? Ban them? Or just let staff use them as normal?

 

If you encrypt them do you have a way to block drives that aren't encrypted?

 

For laptops i am guessing windows 10 bitlocker is the best way to go forward. Do you have this setup on just staff laptops? Or all computers?

 

Thanks

Edited by tj2419
Posted

We're moving to block all USB drives in January, with Sophos device control polices. We will, however, be issuing encrypted memory sticks in exceptional circumstances.

I think Sophos can be set to only block unencrypted devices, but we're going for the block everything with specific exceptions rout.

 

 

And yeah, rolling out bitlocker drive encryption on any offsite laptops.

  • Thanks 1
Posted
And yeah, rolling out bitlocker drive encryption on any offsite laptops.

 

Are you planning on encrypting any onsite laptops or computers? Just thinking incase of a break in or something.

Posted

We are considering blocking USBs and only allowed on a per basis otherwise they will be encrypted. Users will be responsible for them.

 

Laptops will be Bitlocker Windows 10 - gives us the chance to stick W10/SSDs in them.

Posted
Are you planning on encrypting any onsite laptops or computers? Just thinking incase of a break in or something.

As "onsite laptops" are shared pupil use ones, having an extra level of authentication would cause a fair bit of hassle and be time consuming for someone.

Much the same excuse for desktops. We get enough complaints when the wake-on-lan doesn't work for desktops, imagine how much kickback we'd get if they had to punch in a password and wait for it finish booting before logging on.

 

Add to that the fact that all onside machines are domain joined with no user data being saved to the local drives and bitlockering them is more trouble than its worth.

Posted
Add to that the fact that all onside machines are domain joined with no user data being saved to the local drives and bitlockering them is more trouble than its worth.

 

Your servers, however, are probably worth encrypting on that logic. Does anyone here have encrypted servers??

 

We've got Google Drive, so have told staff to either use Drive or password-protect documents if they need to be on a memory stick. To be honest, since getting Drive, we see very few memory sticks in use.

Posted

We BitLocker all staff PCs (desktops and laptops) in case of loss/theft but haven't tackled the USB drive issue yet. Student laptops and desktops, we don't generally bother as there's no pressing need to.

We've always discouraged the use of USBs, however. In most cases, the USBs are used to transfer files to/from a home computer, and are often a fall-back option when something is too large to email, etc. Having tighter restrictions may just create annoyance and push users towards private Dropbox accounts, etc. which I'd rather avoid.

Posted (edited)

Banned via GPO here for everyone except on public area computers. Outside access is via vpn/rdp.

 

And a staff signed statement stating no data will be uploaded / shared etc.

Edited by mikkydoos
Posted
We've recently banned, but it has caused some grumbles. However, it sometimes throws up a training need. The main grumble has been around scanning images to USB sticks. Solution: educate how to 'scan to email'. Oh - and then make sure all our scanning devices that are supposed to support that actually do! We might soften the ban for a small number of cases if a need is proved, but in that case I's support encryption.
Posted
Your servers, however, are probably worth encrypting on that logic. Does anyone here have encrypted servers??
I'm in the process of encrypting my servers, my on-site laptops/desktops don't allow saving locally so I'm no encrypting those.
Posted
Unencrypted are banned for staff, by policy. I provide Kingston Datatraveler Locker+ G3 drives for staff that want them. I haven't started blocking unencrypted drives by GPO, but I am one violation from doing so!
Posted
In my last job I purchased DeviceLock which was group policy based and whitelisted the schools devices. All personal USB sticks, phones, cameras were blocked. Here I do the same thing using the schools Sophos antivirus software. I suggest you find out if your AV software has this functionality. its increasingly popular. Block individual devices or the make and model. All staff here now have to use our purchased encrypted memory sticks. As mentioned this should have been done years ago as required under the Data Protection Act!
Posted
As mentioned this should have been done years ago as required under the Data Protection Act!

Well, not exactly - DPA doesn't say you must use encrypted memory sticks, it says you must protect the data. Policy saying "don't do it" or "if you must do it, password-protect it" is okay. Use of a non-encrypted memory stick with no PII stored on it is fine.

Posted
Use of a non-encrypted memory stick with no PII stored on it is fine.

 

True I guess but you cant rely on every user to remember or follow the policy and it only takes on slip-up to get in trouble. So to me it makes sense not to give them the opportunity to slip up in the first place. Its one less thing that can go wrong if you just don't allow unprotected sticks in the first place. :)

Posted
True I guess but you cant rely on every user to remember or follow the policy and it only takes on slip-up to get in trouble. So to me it makes sense not to give them the opportunity to slip up in the first place. Its one less thing that can go wrong if you just don't allow unprotected sticks in the first place. :)

 

And this is why Data Protection is an exercise in Risk Management ... and we shouldn't expect everything to be black and white.

Posted
I've verbally (and banned in the ICT AUP) all USB Flash Drives. I was planning to apply a physical ban by installing USBDLM, assigning K, L, M, N, O to USB Flash Drives and then blocking these drives via GPO. Unless someone can advise on a better method.
Posted
True I guess but you cant rely on every user to remember or follow the policy and it only takes on slip-up to get in trouble. So to me it makes sense not to give them the opportunity to slip up in the first place. Its one less thing that can go wrong if you just don't allow unprotected sticks in the first place. :)

 

By that measure, I'm assuming you don't have any printers in case someone prints out something sensitive. Or email in case they email something sensitive. Or an Internet connection in case they upload something sensitive.

Posted
Ban on all with ESET Device Control, apart from our photography computers for SD Cards etc. and certain USB's allowed for some staff. Laptops are encrypted with BitLocker and overall the USB ban was okay as we say use OneDrive and they don't really have an excuse.
  • 3 months later...
Posted

We run Sophos End Point Protection with InterceptX

 

Does anyone know if it's possible to restrict USB memory sticks to only those that are encrypted? I can't seem to see how to do it if it's possible...

Posted
We run Sophos End Point Protection with InterceptX

 

Does anyone know if it's possible to restrict USB memory sticks to only those that are encrypted? I can't seem to see how to do it if it's possible...

 

In sophos endpoint, device control policies can differentiate between normal and encrypted usb sticks.

Capture.PNG

Posted
In sophos endpoint, device control policies can differentiate between normal and encrypted usb sticks.

[ATTACH=CONFIG]48004[/ATTACH]

 

Thanks I've found it!

 

This seems to be applicable to the various "groups" I've set up of PC's on cloud central.

So I could ban all non secure memory sticks for all staff PC's...

 

 

Is there a way to link Sophos Central to our AD so we can do policies on our security groups?

Posted

As I understand it, the sophos device control policies are machine policies. We have the enterprise console on a local server that links to AD, but it only allows us to sync computer OUs to Sophos groups.

It sounds like you have a slightly different setup, so you might have more user based options than us though.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...