We are pleased to announce the new “Guide to the use of endpoint encryption with Microsoft BitLocker in terms of the GDPR”. The SEC4YOU guide looks at the requirements of the European General Data Protection Regulation (GDPR) and provides concrete recommendations for client deployment.
From the content
- Evaluation of protection goals for BitLocker (BL) — page 7
- Evaluation of the technical implementation of BL- Page 8
- BitLocker cryptography and authentication- page 8
- Using a secure BitLocker authentication method — page 8
- Threats in power saving mode — page 11
- Monitoring BL encryption — page 11
- Retirement of BL end devices according to ÖNORM S 2109–4 — page 13
- Deletion of BL data carriers by overwriting — Page 13
This guide specifically considers the dangers of storing personal data on Windows mobile devices such as notebooks, tablets, convertible notebooks as well as workstations. As a premise, it is defined that through commercial use of mobile devices, the storage or caching of personal data in emails, customer lists, prospect lists, customer quotes, phone lists, etc. usually occurs.
The following technical measures focus on the encryption of Windows end devices with the widely used Microsoft encryption solution integrated into the operating system and the storage of personal data on the system-integrated hard disk or solid-state disk (SSD).
- The assessments in the guide to the use of endpoint encryption with Microsoft BitLocker in terms of the GDPR
- Evaluation of the Microsoft BitLocker protection goal
- Assessment of which end devices are to be encrypted
- Assessment about the encryption strength and required password length
- Evaluation about the common use of encrypted end devices
- Evaluation of TPM usage without user authentication
- Evaluation of authentication with key on a USB stick
- Evaluation of authentication with key on a USB stick with TPM and TPM PIN
- Evaluation of authentication with TPM PIN
- Evaluation of password authentication
- Evaluation of threats in energy saving modes (standby, hibernation, hybrid)
- Evaluation of the monitoring requirements of the encryption
- Assessment on secure retirement of encrypted BitLocker volumes.
The guide is provided free of charge to interested parties and customers via email download link.
Further DSGVO topics at SEC4YOU: Offer GDPR Readiness Check