Home page logo
/

basics logo Security Basics mailing list archives

RE: Laptop - Full Disk Encryption?
From: "Jason Gifford" <JGifford () paraport com>
Date: Wed, 17 Oct 2007 09:28:05 -0700

 May want to check out PGP's Full Disk Encryption system. On the
enterprise level it does support password recovery.

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of William.Colson () adab centaf af mil
Sent: Wednesday, October 17, 2007 8:09 AM
To: fac51 () yahoo com; security-basics () securityfocus com
Subject: RE: Laptop - Full Disk Encryption?

I'm a bit of a newb myself, but for password recovery we have them
written down and sealed in envelopes then placed in a safe. A trusted
individual has access to them in case someone forgets a password.

Use strong passwords.

Just my $.02

Will

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of fac51
Sent: Wednesday, October 17, 2007 1:05 PM
To: security-basics () securityfocus com
Subject: Laptop - Full Disk Encryption?

Does anyone know of a good full disk encryption product.
It will be used for senior management so it must be easy to use and
recover if the password is forgotten.

Assumptions are that laptop information security is strongest if data is
not saved locally but an audit has revealed otherwise.

Technical Controls (proposed)

1. BIOS password. (currently not enforced) 2. Full disk or partition
encryption. (currently not enforced)

Is there anything else I should take into account?

I have read that encryption is useless if the password that is used is
not strong is this true?


Thanks in advance for any help, greatly appreciated.

S



________________________________________________________________________
____________
Don't let your dream ride pass you by. Make it a reality with Yahoo!
Autos.
http://autos.yahoo.com/index.html




DISCLAIMER: This message is intended only for the personal and confidential use of the designated recipient(s) named 
above. If you are not the intended recipient of this message, you are hereby notified that any review, dissemination, 
distribution or copying of this message is strictly prohibited. This communication is for informational purposes only 
and should not be regarded as an offer to sell or as a solicitation of an offer to buy any financial production, an 
official confirmation of any transaction, or as an official statement of Parametric Portfolio Associates.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault