Educause Security Discussion mailing list archives

Re: Laptop encryption- Follow-up


From: "Patria, Patricia" <PPatria () BENTLEY EDU>
Date: Tue, 16 Nov 2010 11:59:41 -0500

For those that responded to the encryption thread noting that you are using Whole Disk Encryption for portable devices, 
would you mind sharing which group this applies to? Is it just your staff members? Or faculty as well?

We are in the process of rolling out Bitlocker whole disk encryption to all staff with laptops, but are planning to 
allow faculty to opt out of Bitlocker if they sign a waiver stating that they do not store sensitive data on their 
laptop per our Data Classification Policy. Is anyone doing something similar?

From a breach standpoint, if the individual signs a waiver and states that they do not have any sensitive information 
on their computer, do you employ other controls like Identity Finder or DLP software to ensure that is the case? Or is 
their signed waiver enough?

Any feedback, or examples of how you address lost/stolen devices from a breach standpoint, is appreciated. Thank you. 

Patty


Patty Patria
Bentley University
 


Current thread: