|
Hard disk encryption
software is primarily used to protect
confidential data on laptops from being read by unauthorised
users in the event that a laptop is stolen or lost. Each
sector on the hard disk is encrypted separately, generally
using a 256 bit encryption key, so that even if someone
finds a laptop, removes the hard disk and then tries to use
either a brute force attack or rainbow tables to gain access
to the hard disk, it is impossible (within the bounds of
practicality) for them to succeed.
SafeGuard
Enterprise Hard Disk Encryption Software from Utimaco (now owned by
Sophos) combines hard disk encryption with pre boot user
authentication so that the PC cannot be booted from a CD or
floppy which would otherwise potentially enable the attacker
to gain access to the system. A USB Password Token can be
required to authenticate the user as a further level of
security to protect against password guessing or shoulder
surfing. Whilst Microsoft does include Bitlocker encryption
with Vista, there is no central management available for
Bitlocker which increases the cost of ownership in larger
organisations where the cost of managing forgotten passwords
and key recovery far outweighs the extra cost for products
such as
SafeGuard Enterprise which provides central password
recovery which can be undertaken by the user themselves via
a web interface.
Applications for hard disk encryption are increasingly being
driven by regulatory compliance, either by the government’s
Information Commissioner or regulatory bodies such as the
Financial Services Authority (FSA) who now mandate disk
encryption for their members if confidential client
information is held on laptops.
Installation of laptop encryption such as
SafeGuard Device
Encryption is a relatively
straightforward process. Clearview Systems will assist
customers to deploy a trial system for up to 5 users free of
charge where central management is required. For larger
deployments, two days should
be allowed for the process of installing the central
management system, creating a policy, importing users from
Active Directory and preparing a package to distribute to
users. |