Jump to content

Recommended Posts

Posted

Hello fellow travellers on the magical GDPR journey.

 

What are you doing about people with school data on existing USB sticks, that aren't encrypted? My plan is to have IT (who I suspect are liking me less and less each day) run a "we'll secure delete all the personal data for you" service, where Staff just bung all the personal data on their USB sticks into a particular folder, and then bring it to IT who can just sdelete.exe that directory. Not super sure that's good enough though...maybe with some auditing to track everyone who uses a thumb drive over the next few weeks and make sure they all bring it in to be cleansed?

Posted

You could enforce bitlocker to go to disallow write to unencrypted usb - although they could still have stuff on there they could read they won't be able to edit it or add more stuff.

When they plug in it will prompt them to run bitlocker on it - you would need to send a memo with instructions on how to do it.

Posted

I just enable Bitlocker forcing on all drives, read only if they don't enable it. Force it to encrypt the whole drive, backup keys to AD, and have a min 8 char password.

 

Forcing them to not keep them read-only is a human policy, so SLT.

 

In theory you can't sdelete flash anyway, so in theory you'd need to burn them all.

 

Real thing to do is ban usb drives.

Posted
You could enforce bitlocker to go to disallow write to unencrypted usb - although they could still have stuff on there they could read they won't be able to edit it or add more stuff.

When they plug in it will prompt them to run bitlocker on it - you would need to send a memo with instructions on how to do it.

We'll be making them read only anyway, but few if any will ever encrypt them as opposed to just switch to OneDrive. So it's kinda shutting the barn door after the horse has bolted.

 

In theory you can't sdelete flash anyway, so in theory you'd need to burn them all.

 

Because of wear levelling? You can just overwrite all empty space with 0's rather than target the specific file for deletion. That might not be NSA safe, but it should certainly stop any filthy casuals recovering anything.

Posted
We've just written it into the staff handbook, in an ideal world we would never have to use USB, and they should never be removing personally identifiable information from site. but we've stated that taking a non encrypted device - USB or laptop - off site is an immediate disciplinary offence. All *issued* devices are bitlockered, whether they leave site or not, and assigned in asset management.
Posted

Bitlocker is a good option if you dont have Macs. Azure Information Protection/ Windows Information Protection can tag data; stop it going to cloud services or applciations that are not approved.

I think you need a month of read-only and then Deny Read and Write Permissions. Either way there will be some agro; it will also highlight any shadow IT going on to cloud services that are not Office 365 or G-Suite.

Posted
@Oaktech Is that your decision or something from the MAT?

 

I decided, I discussed it with our HR and with the MAT IT. Everyone agreed and the MAT are discussing adopting it trust-wide. It may or may not happen trust wide - but they're happy for us to run the policy.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...