{"id":426,"date":"2017-08-11T13:36:55","date_gmt":"2017-08-11T13:36:55","guid":{"rendered":"https:\/\/eset-blog.aist.fun\/buying-encryption-five-good-questions-to-ask-before-you-do\/"},"modified":"2019-05-29T11:48:15","modified_gmt":"2019-05-29T11:48:15","slug":"buying-encryption-five-good-questions-to-ask-before-you-do","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2017\/08\/11\/buying-encryption-five-good-questions-to-ask-before-you-do\/","title":{"rendered":"Buying encryption? Five good questions to ask before you do"},"content":{"rendered":"<p class=\"wls-paragraph\"><a href=\"https:\/\/encryption.eset.com\" target=\"_blank\" rel=\"noopener noreferrer\">General Data Protection Regulation<\/a> (GDPR) together with the growing number of data breaches are the most pressing reasons why small and medium businesses are implementing data protection technologies \u2013 including encryption.<\/p>\n<p class=\"wls-paragraph\">However,&nbsp;with limited time and the&nbsp;market flooded by various products, it can be a difficult task for companies\u2019 owners and decision-makers to find the right fit for their needs.<\/p>\n<p class=\"wls-paragraph\">If you are faced with the decision yourself, avoid pitfalls in selecting an encryption product by asking the following questions:<\/p>\n<h2>Which laptops present the&nbsp;greater risk: On-site or off-site?<\/h2>\n<p class=\"wls-paragraph\">This might seem like a pointless question with an obvious answer; systems are more liable to theft when away from the office. But making this distinction and keeping it in mind is the right place to start and when you have settled on a solution, be sure to test its effectiveness at managing problem scenarios for your remote users.<\/p>\n<h2>Does the encryption system suit the needs of your IT department for full remote control of off-site endpoint encryption?<\/h2>\n<p><span class=\"block_quote_right\">\u201cALL MAJOR ENDPOINT ENCRYPTION PRODUCTS OFFER THE MEANS TO MANAGE REMOTE SYSTEMS, BUT LOOK CAREFULLY AT THE REQUIREMENTS.\u201d<\/span><\/p>\n<p class=\"wls-paragraph\">All major endpoint encryption products offer the means to manage remote systems, but look carefully at the requirements. Most need either an open incoming connection to a demilitarized zone (DMZ) on your server, or a VPN connection. All involve a higher level of IT skills that can add additional costs and, in order&nbsp;to function, may require the <em>user<\/em> to initiate the connection; not much use with a rogue employee or stolen laptop.<\/p>\n<p class=\"wls-paragraph\">A well-designed product will give you the remote management necessary without creating additional security problems, requiring specialist knowledge, or adding expense to the project.<\/p>\n<h2>Why is this important?<\/h2>\n<p class=\"wls-paragraph\">Being able quickly to&nbsp;vary security policy, encryption keys, features and operation of endpoint encryption remotely, means that your default policy can be strong and tight. Exceptions can be made only when and where they are needed, and reverted just as easily. If you can\u2019t do this you\u2019ll be forced to leave \u2018a key under the doormat\u2019, just in case \u2014&nbsp;tearing holes in your policy before deployment is complete.<\/p>\n<h2>Does the solution allow remote locking&nbsp;and wiping of&nbsp;keys from laptops?<\/h2>\n<p class=\"wls-paragraph\">The answer might be crucial if a company computer with full-disk encryption gets stolen while in sleep mode or with the operating system booted up. It\u2019s even worse if those systems come with the pre-boot password affixed on a label or tucked in the laptop bag. If a remote lock or wipe function is not available, then the system is either unprotected or secured only by the OS password, with the encryption being bypassed in either case.<\/p>\n<p class=\"wls-paragraph\">Similarly, it is important to know whether the solution has been designed to accommodate the typical use cases that would otherwise unravel a well designed security policy.<\/p>\n<h2>Does the solution secure removable media without having to whitelist each item?<\/h2>\n<p class=\"wls-paragraph\"><a  href=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2017\/08\/encryption_usb.jpg\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-98659\" src=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2017\/08\/encryption_usb-300x199.jpg\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" srcset=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2017\/08\/encryption_usb-300x199.jpg 300w, https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2017\/08\/encryption_usb-768x508.jpg 768w, https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2017\/08\/encryption_usb-65x42.jpg 65w, https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2017\/08\/encryption_usb-114x76.jpg 114w, https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2017\/08\/encryption_usb-97x65.jpg 97w, https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2017\/08\/encryption_usb.jpg 1000w\" alt=\"encryption usb \" width=\"640\" height=\"424\"><\/a><\/p>\n<p class=\"wls-paragraph\">With an array of writeable devices that people use for their everyday work, it is almost impossible for the admins to whitelist each and every one of them, and decide whether it\u2019s permissible to read from, write to, or not access the device at all.<\/p>\n<p class=\"wls-paragraph\">It is much easier to set a file-level policy \u2013 distinguishing between files that need encryption and those that don\u2019t \u2013 and keep these protected every time they move from workstation or corporate network to any portable device.<\/p>\n<p class=\"wls-paragraph\">In other words, if you connect your own USB stick, it won\u2019t force you to encrypt your private data; anything coming from the company system, however, will be encrypted without the keys being held on your device.&nbsp;It is a simple idea, but one which makes any device safe, without the need for whitelisting.<\/p>\n<h2><strong>Closing Remarks: The security was there a long time ago; what will make or break your deployment is flexibility and ease of use.<\/strong><\/h2>\n<p class=\"wls-paragraph\">In the end you need to figure out if the solution you want to use is easy to deploy. If the setup of the solution takes hours or even days and needs additional tools for its operation, it might cause new headaches for company sysadmins and create new security risks. Aim for an easy-to-deploy solution that doesn\u2019t require advanced IT expertise and preserves&nbsp;both finances and your&nbsp;human resources. If the user experience mirrors that easy deployment, then IT staff won\u2019t be further taxed by user lockouts, lost data and other frustrations.<\/p>\n<p class=\"wls-paragraph\">All validated, commercial encryption products have been more than strong enough for many years, yet a significant proportion of the recorded data breaches involving lost or stolen laptops and USB drives happened to organizations who had bought and deployed encryption products.<\/p>\n<p class=\"wls-paragraph\">Reading the case notes for these incidents reveals that being able to fit the solution to&nbsp;your environment, working practices and making encryption easy for everyday users as the real challenges.<\/p>\n<p>Source: <a href=\"https:\/\/www.welivesecurity.com\/2017\/08\/17\/encryption-five-good-questions\/\">Welivesecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>General Data Protection Regulation (GDPR) together with the growing number of data breaches are the most pressing reasons why small and medium businesses are implementing data protection technologies \u2013 including encryption. However,&nbsp;with limited time and the&nbsp;market flooded by various products, it can be a difficult task for companies\u2019 owners and decision-makers to find the right [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":1829,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2880,167],"tags":[],"class_list":["post-426","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-security","category-privacy"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/426","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=426"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/426\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/1829"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=426"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=426"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=426"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}