Full disk encryption software is primarily used to protect confidential data on laptops from being read by unauthorised users in the event that a laptop is stolen or lost. Each sector on the hard disk is encrypted separately, generally using a 256 bit encryption key, so that even if someone finds a laptop, removes the hard disk and then tries to use either a brute force attack or rainbow tables to gain access to the hard disk, it is impossible (within the bounds of practicality) for them to succeed.
SafeGuard Enterprise Full Disk Encryption Software from Sophos combines full disk encryption with pre boot user authentication so that the PC cannot be booted from a CD or floppy which would otherwise potentially enable the attacker to gain access to the system. A USB Password Token can be required to authenticate the user as a further level of security to protect against password guessing or shoulder surfing. Whilst Microsoft does include Bitlocker encryption with Vista, there is no central management available for Bitlocker which increases the cost of ownership in larger organisations where the cost of managing forgotten passwords and key recovery far outweighs the extra cost for products such as SafeGuard Enterprise which provides central password recovery which can be undertaken by the user themselves via a web interface.
Applications for full disk encryption are increasingly being driven by regulatory compliance, either by the government’s Information Commissioner or regulatory bodies such as the Financial Services Authority (FSA) who now mandate disk encryption for their members if confidential client information is held on laptops.
Installation of laptop encryption such as SafeGuard Device Encryption is a relatively straightforward process. Clearview Systems will assist customers to deploy a trial system for up to 5 users free of charge where central management is required. For larger deployments, two days should be allowed for the process of installing the central management system, creating a policy, importing users from Active Directory and preparing a package to distribute to users.