Security Basics mailing list archives

RE: Laptop - Full Disk Encryption?


From: "Dias, Tiago Filipe (PT - Lisbon)" <tidias () deloitte pt>
Date: Wed, 17 Oct 2007 17:50:47 +0100

Check out this solution: http://www.winmagic.com/

Tiago Filipe Dias 

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of fac51
Sent: quarta-feira, 17 de Outubro de 2007 10:05
To: security-basics () securityfocus com
Subject: Laptop - Full Disk Encryption?

Does anyone know of a good full disk encryption product.
It will be used for senior management so it must be easy to use and
recover if the password is forgotten.

Assumptions are that laptop information security is strongest if data is
not saved locally but an audit has revealed otherwise.

Technical Controls (proposed)

1. BIOS password. (currently not enforced)
2. Full disk or partition encryption. (currently not enforced)

Is there anything else I should take into account?

I have read that encryption is useless if the password that is used is
not strong is this true?


Thanks in advance for any help, greatly appreciated.

S


 
________________________________________________________________________
____________
Don't let your dream ride pass you by. Make it a reality with Yahoo!
Autos.
http://autos.yahoo.com/index.html 
 
*Disclaimer:*
Deloitte refers to one or more of Deloitte Touche Tohmatsu, a Swiss Verein, its member firms, and their respective 
subsidiaries and affiliates.  As a Swiss Verein (association), neither Deloitte Touche Tohmatsu nor any of its member 
firms has any liability for each other's acts or omissions.  Each of the member firms is a separate and independent 
legal entity operating under the names "Deloitte," "Deloitte & Touche," "Deloitte Touche Tohmatsu," or other related 
names.  Services are provided by the member firms or their subsidiaries or affiliates and not by the Deloitte Touche 
Tohmatsu Verein.
Privileged/Confidential Information may be contained in this message. If you are not the addressee indicated in this 
message (or responsible for delivery of the message to such person), you may not copy or deliver this message to 
anyone. In such case, you should destroy this message and kindly notify the sender by reply email. Please advise 
immediately if you or your employer do not consent to Internet email for messages of this kind. Opinions, conclusions 
and other information in this message that do not relate to the official business of my firm shall be understood as 
neither given nor endorsed by it.


Current thread: