JoeBloggs Posted December 6, 2017 Posted December 6, 2017 Hi all, quick GDPR query. If I have a Windows File Server on a windows domain protected by anti virus, behind a fire wall, in a locked comms room etc. And on this file share is a HR drive locked down by windows security. But obviously the HR drive has some personal information on. Is this shared folder, legally required by GDPR to be encrypted? Thanks
GrumbleDook Posted December 6, 2017 Posted December 6, 2017 Risk assessment. There is no legal requirement for encryption, but it is a good way of mitigating risk. 1
Marci Posted December 6, 2017 Posted December 6, 2017 Additional considerations: Do your HR staff comply with a password complexity policy? Are you the sole key holder to the comms room? Is the comms room secure in case of a break-in? Are all your IT staff with access to that comms room _100%_ trustworthy? Do you have a shared administrator account amongst IT staff? I can think of plenty of reasons why it should be encrypted if requested, and not many for why it shouldn't.
JoeBloggs Posted December 6, 2017 Author Posted December 6, 2017 Additional considerations: Do your HR staff comply with a password complexity policy? Yes Are you the sole key holder to the comms room? No, myself & HR Director Is the comms room secure in case of a break-in? Yes Are all your IT staff with access to that comms room _100%_ trustworthy? Yes Do you have a shared administrator account amongst IT staff? No It hasn't been requested, I wanted to know if it was a legal requirement - lots of sales people have been talking about their encryption software.
GrumbleDook Posted December 6, 2017 Posted December 6, 2017 There are a number of running jokes on GDPR ... one is that the InfoSec response is to encrypt everything! 1
pete Posted December 6, 2017 Posted December 6, 2017 Add in "Can I tell if HR have saved files with sensitive personal data somewhere they shouldn't / taken them somewhere they shouldn't?" "If I'm using file-based encryption, is it configured in such a way there's a get-out-of-jail mechanism if Fred (in HR) gets hit by a bus?" "Have I got auditing* turned on for shares / folder trees containing personal data?"
PotNoodleTech Posted December 7, 2017 Posted December 7, 2017 In my humble opinion, all file servers should be encrypted as this prevents data breech if the physical hardware were ever stolen. In the process of securing funding to do that to my servers ready for next May.
tinkerbotsict Posted December 7, 2017 Posted December 7, 2017 Yeah everything should be encrypted makes one less headache
JoeBloggs Posted December 7, 2017 Author Posted December 7, 2017 What software will you use to encrypt Windows Server Shares?
free780 Posted December 7, 2017 Posted December 7, 2017 You could bitlocker your server but keep a recovery key separate from AD somewhere secure. Just in case.
tinkerbotsict Posted December 7, 2017 Posted December 7, 2017 We use bitlocker on staff laptops that go off site
JoeBloggs Posted December 8, 2017 Author Posted December 8, 2017 Yes we use BitLocker for laptops. Everyone BitLockers servers? We're running predominantly Server 2008 R2.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now