Wednesday, May 21, 2008

GuardianEdge for Hard Disk Encryption

Loss and theft of laptops and USB drives is one of the biggest security threats out there, and I need to know more about the products that support encryption.

If all the important information stored on your laptop and USB sticks are encrypted (the the laptop is OFF, or in a state where it needs a password to decrypt), then loss and theft aren't a security risk.

Just having a product that encrypts the data isn't enough, it has a good algorithm (like AES) and it has to be trusted. This means Common Criteria or FIPS 140-2 validation (or both). It also needs things like key escrow, so lost passwords aren't permanent.

I just talked to GuardianEdge as a solution for both full disk and removable storage encryption. It was a good meeting and an impressive product. We'll load it up on VMWare on both XP and Vista and kick the tires. It's both Active Directory integrated and FIPS 140-2 validated.

Has anyone worked with these products or worked with others in the same space?

No comments: