Jump to content

Recommended Posts

Posted

Hi All,

 

Just a silly question to ask if the BitLocker encryption (or any encrytion method) required to enforce on all the hardisks of the school laptops, PC and external memory sticks, by the DfE policy or any data securiy & protection policy of UK?

 

Is there any exemption? Or will there by any consequence from the authorities if the school does not apply the Bitlocker or any encryption?

 

Thanks for your comments.

Posted

Its's uninvasive enough to warrant having it on all school owned devices these days, but at the very least it should be on for staff laptops & desktops.

It's not so much rules and regulations, but risk mitigation should something happen such as the theft of a device. Many modern setups means there is very little to no information stored on local laptops any more, but there are still cached files which could be an issue if they fell into the wrong hands.

Obviously this is much less of an issue for students.

Posted
Hi All,

 

Just a silly question to ask if the BitLocker encryption (or any encrytion method) required to enforce on all the hardisks of the school laptops, PC and external memory sticks, by the DfE policy or any data securiy & protection policy of UK?

 

Is there any exemption? Or will there by any consequence from the authorities if the school does not apply the Bitlocker or any encryption?

 

Thanks for your comments.

 

 

Theres no reason to not have it enabled on everything where it can be implemented transparently to the user. if for nothing else than the reasurance if its stolen its not open... now that doesnt get around postits with passwords...

 

as for the later, you will be asked to justify why it isnt adequately protected if there is a breech resulting from it id assume and repercussions because of that.

 

with regards to external storage, block it all, save yourself the headache, we all have cloud storage now so theres no need.

Posted
There isn't a requirement for encryption specifically, but GDPR dictates that data must be secure. This means that you have to consider scenarios where sensitive data could be accessed, which includes (but not limited to) lost/stolen portable drives/laptops, physical theft of server equipment or unauthorised data access on-site/remote. You can't use the argument that there's no specific requirement to use encryption, because it is the school's responsibility to ensure that the data cannot be accessed by unauthorised persons. That's why you should be using encryption and BitLocker happens to be included within Windows for free (management tools may require extra licensing).
Posted
It's not specifically required. It's a good idea going forward. With Windows 11, we'll have all devices on TPM 2.0+ so we will then enforce it on everything where it's currently just on staff laptops.
Posted

At the very very least, you should be doing all laptops as they are frequently taken off site.

 

Otherwise, anyone could just rip out the storage drive, plug it into another machnie & access everything on the local drive.

Posted

We force bitlocker on external drives, staff laptops and anything that isn't connected to the domain. We have a PC that does funky stuff with the DT hardware and the IT tech machines are bit locked also.

 

We don't have it enabled on clients as everything get saved back to the servers...... although the server's aren't bit locked either.

Posted

https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/laptop-desktop-and-tablet-standards#devices-should-be-safe-and-secure

 

I'm sure this used to explicitly call out the need for encryption, but it seems to have been removed. However it cites https://www.ncsc.gov.uk/collection/device-security-guidance as guidance on how to achieve this standard, and *that* does state that encryption should be applied.

 

The GDPR's impact is covered here, with a check list to self-evaluate your posture. I really don't see how you could end up in a place where a school's data protection policy doesn't implicitly (or explicitly) require you to encrypt all devices. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/

 

There is wiggle room (assessment of feasibility/cost etc), but if your devices have a TPM / Secure Enclave / Equivalent they should be encrypted, and your policies should state this. We still have some devices which do not have TPMs. Staff are not permitted to use these, and they will all have been replaced by September.

Posted

On our laptops (including those that don't have a TPM chip in them), we enable Bitlocker and have a Windows Pre-boot password so each laptop that is assigned to a user has to put this password in.

 

Works well here, staff understand why.

  • Thanks 1
Posted

It's worth also having some means to report on which devices have BitLocker protection actually in place. Some of our models will begin encrypting automatically according to GPO settings, but some models won't, even though it can be started manually just fine (for some obscure hardware spec reason).

 

If there's any scope for encryption not beginning automatically, then you need to have that showing up in a report somehow.

 

We use GLPI, so I have a saved search which checks for any non-encrypted system volumes on clients.

Posted
Bitlocker save our day last year. We have it set to also need a pin number on boot. The business manager left the school laptop in the back of her car over night and it was gone in the morning. About 6 hours later it was found about a mile away in a hedge. I'm guessing whoever took it, turned it on and couldn't get it to boot so dumped it.
Posted

It's worth it to save the pain of not having to report a list or stolen laptop to the ICO because it's almost guaranteed to be a data breach. Also note, you need evidence that the device was encrypted and that's where managed Bitlocker scores.

 

All of that is just a side effect of the main event: you no longer have to worry about confidential data causing harm to an individual or the school when someone loses a device.

Posted
Nothing required ‘legally’ but just do it. Users won’t even know for the most part. Just make sure you store the recovery key somewhere.
Posted

Assuming you have the patches actually installed https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20666 and updated the winre partition

 

And when you patched the 2017 vuln on tpm 1.2 devices you actually reset the key https://support.microsoft.com/en-gb/topic/bitlocker-mitigation-plan-for-vulnerability-in-tpm-6588b5bb-a799-5983-a7a1-f1340e9beac3

 

And the TPM firmware doesn't have bugs https://www.bleepingcomputer.com/news/security/new-tpm-20-flaws-could-let-hackers-steal-cryptographic-keys/

Posted
Many modern setups means there is very little to no information stored on local laptops any more

 

Really? I have my OneDrive synced to my laptop, so presumably those files would all be freely accessible if you just pop the hard drive out.

 

As you say, it really isn't that onerous a task to put an extra PIN code in when turning on/waking the laptop, so just make it compulsory.

  • Thanks 1
Posted

As others have said, I don't believe encryption is compulsory as such. I mean it isn't quite the word I'd use, but it is 'implied' by other standards and is more to do with the fallout if something happens.

 

It's a bit like insurance (apart from vehicle insurance which IS legally required/compulsory)... It might be fine if you haven't got it, but when something happens and you are asked why you didn't have that laptop encrypted (especially as AFAIK a lot of other 'recommendations/guidance/standards' and I think GDPR legislation requires you to have taken all 'possible steps to secure the data'), there's not much room to wriggle out of it with any other interpretation. So it's not compulsory, but there is no way you wouldn't do it.... if you see what I mean?

 

IIRC at least 12 years ago we had an email from the ex-LEA IT support team consultants regarding the E-Safety tools they were 'recommending' for schools. I'm sure that came from some Gov. guidance at the time...

 

For encryption they were recommending DESlock rather than the Windows 7 version of Bitlocker (maybe not everyone was running an Enterprise version and this was seen as being able to 'cover all bases').

 

However, at the time I chose to go with Truecrypt (which a few years later I believe was rumoured to be unsafe and was possibly forked into other open source versions), but we'd started on to Windows 10 the year or so after anyway. I think with anything like this it's a risk assessment job and at the time I believed even if it was able to be cracked somehow (not actually sure it was), I doubted anyone would go to such lengths.

 

Ours use a password to bypass the need for TPM compatibility, we do not allow any removable USB drives.

Posted

What about desktop PCs? How many people encrypt those, since it wouldn't be all that complex for someone breaking in to take them?

 

What about servers? it would make scheduled reboots a bit harder (or you could disable Bitlocker first) but again, someone could get those disks out, or take the entire systems. Less likely than desktops, but not at all impossible.

Posted
What about desktop PCs? How many people encrypt those, since it wouldn't be all that complex for someone breaking in to take them?

 

What about servers? it would make scheduled reboots a bit harder (or you could disable Bitlocker first) but again, someone could get those disks out, or take the entire systems. Less likely than desktops, but not at all impossible.

I've created a collection in SCCM of all workstations that do not meet TPM 1.2 or have secure boot enabled and I'm making my way round, slowly but surely and enabling them. I want to get to a point where I can have a high-level policy that applies the same BitLocker rules to all clients, then it's a case of set and forget. I haven't considered servers yet, I know I can use BitLocker on the Windows servers, VMware offers VM encryption and I think the HP iLO also offers encryption.

Posted

We encrypt our desktop PCs just the same as we do laptops.

 

Part of our post-imaging workflow is to check that BitLocker is enabled. In fact, it's pretty much the only part of our post-imaging workflow. Realtively easy for us as everything has a TPM.

Posted

We bitlocker all our user devices, there is no good reason not to. I get my data encrypted at rest and whilst it can be argued how useful this is, at the very least it ticks the box for the auditors. There are some potential weaknesses with it as discussed above but there are potential weaknesses with any thing in IT.

 

It takes a couple of seconds to setup and has no measurable impact on the end user as long as you keep a copy of the recover keys it's painless. As I said why not bitlocker?

  • Thanks 1
Posted (edited)

I doubt any high level standard is going to say "You must use PRODUCT NAME", so you probably won't find a requirement for "bitlocker".

 

Having said that, you probably will have requirements to keep the personal data pertaining to sdtudents and staff secure, and if data is stored on a end-user device such as a Windows laptop, bitlocker may well be the cheapest, easiest way to meet the requirement.

 

So, unless your data is stored on Windows 365 devices so is never on the laptop, or unless your laptops are Chrome OS, MacOS or Linux, then as others have said "why not Bitlocker"?

Edited by Roberto
Posted
So, unless your data is stored on Windows 365 devices so is never on the laptop, or unless your laptops are Chrome OS, MacOS or Linux, then as others have said "why not Bitlocker"?

 

Data in 365 doesn't mean it isn't on the laptop. Aside cached files, OneDrive sync stores offline copies of any files you work on.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...