Alastairb25 Posted April 12, 2018 Posted April 12, 2018 (edited) Hi, Given the impending GDPR deadline I am curious to know the practical approaches being taken.. My thoughts so far, in no particular order are.. Blocking USB Storage devices, enforced via GPO Perhaps an option to read but not write, however given the dangers of Sticks being used to carry malware / viruses into a Site I prefer the a total Block. Laptops Pull them all back in, Ensure asset details are logged correctly, Smartwater, Remove existing HDD and store securely incase important files need recovered, Rebuild with SSD and have purely as an Access device, ie RDP via VPN or RDP locally if on Site Emails Mixture of Office 365 and Hosted Exchange Hosted Exchange at One site to be migrated to 365 Possible Azure Rights Management or Encryption system, not sure which route yet Potentially blocking attachments, should it really be needed?, perhaps replace by emailing Onedrive link General GPO Logon Notice Disclaimer / AUP Lock screen after X minutes RDP Server GPO Settings Change to access via VPN Logoff Disconnected Sessions Block USB Device, Clipboard and Printing Personnel Files and Alike Requirement for Higher level of Security, EFS possibly Need to encrypt files on a Shared folder to which multiple users have access Other thoughts.. Buying an Encryption system seems the most likely answer, I have briefly tested ESET's offering, beyond that and Bitlocker are there any others worth taking a look at? How it actually will work when Teachers complain about not being able to use Sticks etc will be interesting.. Thanks, Alastair Edited April 12, 2018 by Alastairb25
localzuk Posted April 12, 2018 Posted April 12, 2018 (edited) Blocking USB Storage devices, enforced via GPO - Yup Laptops Bitlocker Encryption. Emails Office 365 combined with education of staff General GPO Logon Notice Disclaimer / AUP - Yup Lock screen after X minutes - Yup RDP Servers Web Gateway - SSL encrypted. Logoff Disconnected SessionsB lock USB Device, Clipboard and Printing on devices Personnel Files and Alike Controlled by security permissions, and most stored in specific pieces of software (eg PS People). Other thoughts Rewrite AUPs, Data Protection policies etc. All staff have to understand and sign. Training to be given. Regular reminders regarding behaviours of staff. Edited April 12, 2018 by localzuk
RLR Posted April 12, 2018 Posted April 12, 2018 What are people saying in their Logon Notice Disclaimers?
Alastairb25 Posted April 12, 2018 Author Posted April 12, 2018 (edited) SSL we do already, however I prefer VPN method.. PS People - Interesting, so in order to secure files etc perhaps look at a separate system to Cover HR.. With HR files I meant the fact as an Administrator you could access these files has been raised, beyond encrypting via a system such as EFS I am not sure how best to tackle that one.. Disclaimer text I guess is subjective, as long as you have something, likely referring them to a Policy? otherwise it could be to impractical Edited April 12, 2018 by Alastairb25
localzuk Posted April 12, 2018 Posted April 12, 2018 SSL we do already, however I prefer VPN method.. Why? Encryption is encryption... With HR files I meant the fact as an Administrator you could access these files has been raised, beyond encrypting via a system such as EFS I am not sure how best to tackle that one.. That will always be the case, and is a necessity for any organisation running a network - as, quite simply, if you encrypt you need a way to recover in the event of failure. If that failure is the loss of staff who knew the encryption password, you're scuppered. I would suggest simply removing admin privs from the files as standard, and enabling file auditing on those sorts of files.
djrscally Posted April 12, 2018 Posted April 12, 2018 (edited) Laptops Pull them all back in, Ensure asset details are logged correctly, Smartwater, Remove existing HDD and store securely incase important files need recovered, Rebuild with SSD and have purely as an Access device, ie RDP via VPN or RDP locally if on Site Why on earth RDP on site? Enforcing RDP externally as opposed to just encrypting the disk is already pretty tinfoil, RDP on site is baffling me. I think unless you're super duper confident in your VPN and RDP connections that one might cross the "stuff needs to be very easy to use too" line. Edit: Actually I guess it's just "enforce RDP" which means it has to be used on-site too. So ignore me; makes sense. Everything else you listed seems pretty in line with what I've seen around here. For other encryption thingies; VeraCrypt is the FOSS one, and works really well. Not sure it can be deployed by an NM though as I've never tried to use it like that. Edited April 12, 2018 by djrscally
Alastairb25 Posted April 16, 2018 Author Posted April 16, 2018 I found in the past having link to RDP on desktop for Staff, ie member of an AD group can prove useful. Means they can use SIMS etc from any PC and during an upgrade of SIMS if you have any issues you can just fix the RDP server and have them use that whilst you get time to fix clients
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now