Hi,
Given the impending GDPR deadline I am curious to know the practical approaches being taken..
My thoughts so far, in no particular order are..
Blocking USB Storage devices, enforced via GPO
Perhaps an option to read but not write, however given the dangers of Sticks being used to carry malware / viruses into a Site I prefer the a total Block.
Laptops
Pull them all back in, Ensure asset details are logged correctly, Smartwater, Remove existing HDD and store securely incase important files need recovered, Rebuild with SSD and have purely as an Access device, ie RDP via VPN or RDP locally if on Site
Emails
Mixture of Office 365 and Hosted Exchange
Hosted Exchange at One site to be migrated to 365
Possible Azure Rights Management or Encryption system, not sure which route yet
Potentially blocking attachments, should it really be needed?, perhaps replace by emailing Onedrive link
General GPO
Logon Notice Disclaimer / AUP
Lock screen after X minutes
RDP Server GPO Settings
Change to access via VPN
Logoff Disconnected Sessions
Block USB Device, Clipboard and Printing
Personnel Files and Alike
Requirement for Higher level of Security, EFS possibly
Need to encrypt files on a Shared folder to which multiple users have access
Other thoughts..
Buying an Encryption system seems the most likely answer, I have briefly tested ESET's offering, beyond that and Bitlocker are there any others worth taking a look at?
How it actually will work when Teachers complain about not being able to use Sticks etc will be interesting..
Thanks,
Alastair