Data Encryption
In June 2005, UT System released UTS165, the Information Resources Use and Security Policy which requires that laptops with sensitive data be encrypted. The policy is further defined within Security Practice Bulletin #1 (SPB-1 in PDF).
Data Classification
The UTSA Information Security Office has developed the Data Classification Standard to help you determine the sensitivity of your data. While whole disk encryption is required for all laptops that contain Category I and Category II data, encryption and passwords are recommended for all portable devices to ensure that your data is secure.
Encryption Tools
There are various data encryption software applications available. Here are a few that are recommended by the Information Security Office:
- SafeBoot (preferred) - site license available for UTSA users
- TrueCrypt (open source)
- BitLocker (Vista)
- FileVault (Mac OSX)
SafeBoot
UT System has contracted with SafeBoot to provide an encryption solution for PCs. SafeBoot is a whole disk encryption solution designed for Windows-based machines. SafeBoot works by using its driver to encrypt every piece of data written to the disk; it also decrypts every piece of information read off the disk.
More information on SafeBoot, including purchasing instructions, can be found on the SafeBoot page.
BitLocker (MS Windows Vista)
BitLocker Drive Encryption is a full disk encryption feature included with Microsoft's Windows Vista Ultimate, Windows Vista Enterprise, Windows Server 2008 and Windows 7 Ultimate Beta operating systems. It is designed to protect data by providing encryption for entire volumes. More information on BitLocker is available in this Wikipedia entry.
FileVault (Mac OSX)
FileVault is a system that protects files on Macintosh personal computers. It is available in the Mac OS X v10.3 ("Panther") operating system and newer versions. Learn more about FileVault through Wikipedia.
TrueCrypt (open source)
TrueCrypt is a software application used for real-time, "on-the-fly" encryption. It can create a virtual encrypted disk within a file or a device-hosted encrypted volume on either an individual partition or an entire storage device. It supports Microsoft Windows, Mac OS X and Linux. Encrypted volumes can be made portable. The version for Windows Vista or XP can encrypt the boot partition or the entire boot drive. It has the ability to create and run a hidden encrypted operating system using "deniable encryption" features. TrueCrypt is distributed under the TrueCrypt Collective License. For more information, read the TrueCrypt Wikipedia entry.
Tools