Security Basics mailing list archives

Protecting sensitive files on a Windows file server


From: "paul.johnson8 () gmail com" <paul.johnson8 () gmail com>
Date: Tue, 20 Jun 2006 09:39:27 +1000

We are looking for a secure way to store very sensitive files on our
Windows servers.  The data is shared. We will turn on full auditing,
create hidden shares and a security group.

Which type of protection would be most suitable:

Office 2003 encryption
Windows EFS
Winzip 9.x encrypted archives
RSA SecurID Windows Agent (2 factor authentication)
PGP Desktop Pro

Our concern with the Windows/Office encryption types is that it could
be cracked - ie. someone could get hold of the file and run some kind
of password recovery on the file and access the data.

Any ideas on how to approach this would be much appreciated.


Current thread: