Full disk encryption: A practitioner’s advice, Part 2

Opinion
Jul 30, 20074 mins

* More practical advice from Sean Steele of infoLock Technologies

In last week’s newsletter, security expert Sean Steele of infoLock Technologies gave some pointers of what to look for when you are choosing a full disk encryption solution for your company. This week we’ll continue with more of Sean’s practical advice. His company has evaluated several products in terms of technical features and capabilities, ease of administration and support, and the user experience. As a security systems integrator, infoLock has extensive experience in implementing many types of solutions for its clients.

* How does the encryption product fit into your current infrastructure?

Sean says it’s important that a full disk encryption product fit in with what you already have installed. For example, integration with your directory services is helpful. Sean also favors products that can be administered through your current management tools. “We avoid products that require a separate management structure and console,” he says. Companies don’t have the resources to devote someone to learning a new management tool. Your encryption tool should fit in with what you already use.”

* How does an administrator recover a “bad” encrypted disk?

While hard disks are becoming much more reliable, they do go bad from time to time. This is always bad news, but especially so if the disk has been fully encrypted. If the master boot partition is corrupted, you can’t log on to the disk at all to decrypt it and recover the data. Sean advises to ask your encryption software vendor if it provides a master utility that allows recovery of data in the event of a disk failure.

* How does the software work with disk imaging (i.e., “ghosting”)?

Many administrators use disk imaging, or ghosting, as a shortcut to setting up hard disks that have to have identical or very similar configurations, like when a user gets a new PC and everything has to be copied over from the old to the new computer. This is a fairly easy activity, unless the disk to be copied is fully encrypted. “Decryption of an entire disk is non-trivial,” says Sean. “You don’t want to have to do this to ghost a PC.” He recommends you ask the software vendor how this works, and then test it yourself.

* Can a disk be removed and mounted on another machine in order to circumvent the encryption? What (if anything) can be done with the encrypted contents?

Sean points out that such a scenario can happen under the Windows environment. Someone can pull an encrypted disk off a Windows-based PC and put it on another machine under a different OS and make an end run around the security that’s there. “It depends on the access control built into the software,” says Sean. He recommends asking your encryption vendor about this specific issue so you understand how to prevent the end run.

Sean’s checklist of considerations for full disk encryption is quite thorough. (We’ve only presented a portion of the items in these two articles.) According to Sean, full disk encryption has to be considered in the broader context of endpoint security and data loss prevention.

“Protecting your data is so multi-layered today that there’s no ‘clean’ way to look at it,” says Sean. “In my opinion, you need to start with the data and then consider the risks to the data. From there you can build the methods that protect the data. Some tools are data or device centric, and others focus on network monitoring. There’s no one ‘best way’ to protect your assets.”

But you knew that already.

If you want help making sense of full disk encryption (or a broader data security program) for your organization, e-mail Sean to ask for his list of high-level considerations. It’s a great place to start the conversation for planning for better data security.