Jump to content

Recommended Posts

Posted (edited)

Hi,

 

Given the impending GDPR deadline I am curious to know the practical approaches being taken..

 

My thoughts so far, in no particular order are..

 

Blocking USB Storage devices, enforced via GPO

Perhaps an option to read but not write, however given the dangers of Sticks being used to carry malware / viruses into a Site I prefer the a total Block.

 

Laptops

Pull them all back in, Ensure asset details are logged correctly, Smartwater, Remove existing HDD and store securely incase important files need recovered, Rebuild with SSD and have purely as an Access device, ie RDP via VPN or RDP locally if on Site

 

Emails

Mixture of Office 365 and Hosted Exchange

Hosted Exchange at One site to be migrated to 365

Possible Azure Rights Management or Encryption system, not sure which route yet

Potentially blocking attachments, should it really be needed?, perhaps replace by emailing Onedrive link

 

General GPO

Logon Notice Disclaimer / AUP

Lock screen after X minutes

 

RDP Server GPO Settings

Change to access via VPN

Logoff Disconnected Sessions

Block USB Device, Clipboard and Printing

 

Personnel Files and Alike

Requirement for Higher level of Security, EFS possibly

Need to encrypt files on a Shared folder to which multiple users have access

 

Other thoughts..

Buying an Encryption system seems the most likely answer, I have briefly tested ESET's offering, beyond that and Bitlocker are there any others worth taking a look at?

 

 

How it actually will work when Teachers complain about not being able to use Sticks etc will be interesting..

 

 

Thanks,

Alastair

Edited by Alastairb25
Posted (edited)

Blocking USB Storage devices, enforced via GPO - Yup

 

Laptops

Bitlocker Encryption.

 

Emails

Office 365 combined with education of staff

 

General GPO

Logon Notice Disclaimer / AUP - Yup

Lock screen after X minutes - Yup

 

RDP Servers

Web Gateway - SSL encrypted.

Logoff Disconnected SessionsB

lock USB Device, Clipboard and Printing on devices

 

Personnel Files and Alike

Controlled by security permissions, and most stored in specific pieces of software (eg PS People).

Other thoughts

Rewrite AUPs, Data Protection policies etc. All staff have to understand and sign. Training to be given. Regular reminders regarding behaviours of staff.

Edited by localzuk
Posted (edited)

SSL we do already, however I prefer VPN method..

 

PS People - Interesting, so in order to secure files etc perhaps look at a separate system to Cover HR..

 

With HR files I meant the fact as an Administrator you could access these files has been raised, beyond encrypting via a system such as EFS I am not sure how best to tackle that one..

 

Disclaimer text I guess is subjective, as long as you have something, likely referring them to a Policy? otherwise it could be to impractical

Edited by Alastairb25
Posted
SSL we do already, however I prefer VPN method..

 

Why? Encryption is encryption...

With HR files I meant the fact as an Administrator you could access these files has been raised, beyond encrypting via a system such as EFS I am not sure how best to tackle that one..

 

That will always be the case, and is a necessity for any organisation running a network - as, quite simply, if you encrypt you need a way to recover in the event of failure. If that failure is the loss of staff who knew the encryption password, you're scuppered. I would suggest simply removing admin privs from the files as standard, and enabling file auditing on those sorts of files.

Posted (edited)
Laptops

Pull them all back in, Ensure asset details are logged correctly, Smartwater, Remove existing HDD and store securely incase important files need recovered, Rebuild with SSD and have purely as an Access device, ie RDP via VPN or RDP locally if on Site

 

Why on earth RDP on site? Enforcing RDP externally as opposed to just encrypting the disk is already pretty tinfoil, RDP on site is baffling me. I think unless you're super duper confident in your VPN and RDP connections that one might cross the "stuff needs to be very ​easy to use too" line.

 

Edit: Actually I guess it's just "enforce RDP" which means it has to be used on-site too. So ignore me; makes sense.

 

Everything else you listed seems pretty in line with what I've seen around here.

 

For other encryption thingies; VeraCrypt is the FOSS one, and works really well. Not sure it can be deployed by an NM though as I've never tried to use it like that.

Edited by djrscally
Posted

I found in the past having link to RDP on desktop for Staff, ie member of an AD group can prove useful.

 

Means they can use SIMS etc from any PC and during an upgrade of SIMS if you have any issues you can just fix the RDP server and have them use that whilst you get time to fix clients

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...