DECRYPTING ENCRYPTION: GAINING COMPETENCE ON ENCRYPTION FOR YOUR PRACTICE
|
|
|
- Della Bradley
- 10 years ago
- Views:
Transcription
1 DECRYPTING ENCRYPTION: GAINING COMPETENCE ON ENCRYPTION FOR YOUR PRACTICE Presented by the American Bar Association Legal Technology Resource Center, Law Practice Division and Center for Professional Development
2 American Bar Association Center for Professional Development 321 North Clark Street, Suite 1900 Chicago, IL CDs, DVDs, ONLINE COURSES, DOWNLOADS, and COURSE MATERIALS ABA self-study products are offered in a variety of formats. Find our full range of options at Submit a Question Visit to submit a question on the content of this course to program faculty. We ll route your question to a faculty member or qualified commentator in 2 business days. The materials contained herein represent the opinions of the authors and editors and should not be construed to be the action of the American Bar Association Legal Technology Resource Center, Law Practice Division or Center for Professional Development unless adopted pursuant to the bylaws of the Association. Nothing contained in this book is to be considered as the rendering of legal advice for specific cases, and readers are responsible for obtaining such advice from their own legal counsel. This book and any forms and agreements herein are intended for educational and informational purposes only American Bar Association. All rights reserved. This publication accompanies the audio program entitled Decrypting Encryption: Gaining Competence on Encryption for Your Practice broadcast on August 27, 2015 (event code: CE1508DEG).
3 TABLE OF CONTENTS 1. Presentation Slides 2. Decrypting Encryption: Gaining Competence on Encryption for Your Practice Dave Ries and John Simek
4 1
5
6 David G. Ries John W. Simek
7 Why Encryption Is Needed Up to 70% of data breaches involve laptops & portable media. About 10% of laptops are stolen during their useful lives. 1.4 million smartphones were lost during million smartphones were stolen during
8 Why Encryption Is Needed 2007: 18 laptops were stolen from the offices of a law firm in Orlando. - Protected by encryption - SANS Institute: (laptop stolen, but the data was protected) shouldn t be newsworthy... Encryption protects data! 4
9 Why Encryption Is Needed Electronic communications can be intercepted. Wired and wireless network traffic can be intercepted. Cyberspace is a dangerous place! 5
10 Why Encryption Is Needed PRISM Web-based Telephone records Text messages Social media sites ISP communications VoIP File transfer Video conferencing 6
11 Why Encryption Is Needed July 7,
12 Attorneys Avoid Encryption Encryption 10 FT 8
13 Encryption An electronic process to protect data Transforms readable data into unreadable data Requires a key to make data readable again 9
14 Encryption Readable Plaintext Encryption Key Unreadable Ciphertext Decryption Key Readable Plaintext 10
15 11
16 12
17 Encryption Key Example AES-256 Key +30NbBBMy7+1BumpfmN8QPHrwQr36/vBvaFLgQM561Q= 13
18 Encryption Key -----BEGIN PGP PRIVATE KEY BLOCK----- Version: BCPG C# v lqosbfionhgbcacwahcybg5x52ikbikpen21wea3kr+elvqrkdjd1ol1o4kmy3hh Zz1l/DH7RcZX+efCP3RfEvi7Mu3a9KIEq0D0KxLQbhaWvVDzJ8yUCR8kRepFDKtj pj1g/049djgm4ayhqhmtpsnwrnpbtv5ci2k9cwgzsnh/4nnkagyudsftreoxosut pfytymeogbg2dkng4yz6ug86v5k641lgh9qabajjffxoe2amwbypmwqdahjlczfh U2q05GJt/2zThnky/D//savhrshpNxr1ddEa1QwgGSR/EDPkflv1b4yWH05DbRST dr9b136kh+2ymdtqaj75hhu/h9q6wmhbailxabebaah/awmcozz7ekyu0yzgxuod EoYlOwJmlu/ZLx2GSFtZO2RNyvblG+O3ZeKukG1xbSvzBS0Z5OjQOYnD+X5arvNM DmpyilKpb5DueaN1osxPOkunqQ6cJlOWdROvUQkgLCD7Y7jfu4/coeK+HZuoIHSq txeqaictdcenfyjdjnyngwkj6wft3lgjdhcreck6mzcggjhjmcn8vf+yemsuikm+ 9D/US/rl/lWnINlfgmhiN1NxpAhg9Xo43Mpwex3hZLXLrbhdTkRMVgHLEH5h3xxo /UyNGCn3T9CTa4/vNdmZmMlAAHQk6F0ZhqFLS8x3sR2hxwkaNGmGHRr/ihklv15U RrggHzH89zxc3RDC8al/wcieM1vXx9hK195r9NPJ/hET1EIqs3wLu8rmZDPazIVT j8bqdhh3x964q70ciirevxby29uwsxkhu6q8agmcddegoz/bhtlayss6q53dgw97 U2IN6QIxHDTa+eZU5t1RVR5ugHph6yhTk6rCQF+FTsiaezwHkXqS5SfyNJ2JgOCi 6l4HpA2gLOy3raV4MoSpsEwIpquTccu/B8Aiucy6UL7IELOAMT2s7c2R7qVoBvew 5e2gDid0CWNqN03Zvg4USKq3lYskMUWUtaaexDWNALB210OKixm6mGN4VzelmqMK w6drwwbfuo+xt540wlgooucjzoem+qxkofndzicdq9lns/eswvlzs2l/ei3kf4du B0wexeG7R5eNlOlDfReyz5qWXOLgS47In6OLBXlUfuuNsI0m64DM3Z9LBXev2TuG YHGG26j1FRwgOdSDynjITA2xZrIJQ7rBjJhiMedH1bLlUau75EU/qQVAV1jZ+qD/ CbD/vxVW237NaAPPlctGXrvWMyZh/PSjb/wC56veYrQAiQEcBBABAgAGBQJSDpx4 AAoJEKJQRE9Opr2dRb8H/A67kPkY8fwCY8JxF6tV46rmXIyPOsVzVHb+TG9p+0ep 1js13t1MGJuMS7CXaDdtPdahD9IKwKRO3z2Jxsg2ADYditkR7QUknGUnrJsQOkKx 8gXinRihRNjM2JzsqWkBEOauIlnO5+Y01g7KTo93N1F+pNrPNzRko8gAPWIozJMd 5wLT9NvtdJLRumJjTjQ9ydyLa41uOq8EZvYELwyq0USO5AzlOu5XAduduRv9qhIm CmN8RLgShJzCGhu2E08hgU2kZZtY1g3VyGnttkkn4Vtr6wREh5SyvMlzirWAMb1G LvaFZWAYAPLlCtCZQU3pL8mjFTFAxsKS1CcRLUrOkLM= =9Ry END PGP PRIVATE KEY BLOCK
19 Encryption Program Algorithm Key A Simplified Overview 15
20 Data at Rest Protect Servers, Desktops, Laptops, Tablets, Portable Media, Smartphones, etc. Data in Motion Wired Networks, Wireless Networks, Internet, Cell Networks, etc. 16
21 Is Encryption Too Difficult? AES ALGORITHM Source: quadibloc.com 17
22 Is Encryption Too Difficult? USENIX Security Symposium Aug
23 Is Encryption Too Difficult? Attorneys will often need assistance in setting up encryption. There are now many easy to use options for encryption (particularly after setup). 19
24 Attorneys Duty to Safeguard Ethics Rules Common Law Contracts Statutes and Regulations 20
25 ABA Ethics 20/20 Amendments Model Rule 1.1 Competence Comment [8] To maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology 21
26 ABA Ethics 20/20 Amendments Model Rule 1.6 Confidentiality (c) A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. 22
27 Ethics Opinions - Encryption New Jersey Opinion 701 (2006) California Formal Opinion No Pennsylvania Formal Opinion Texas Opinion No. 648 (2015) 23
28 Unencrypted = A Postcard Bruce Schneier (1995, ) Larry Rogers (2001) ( written in pencil ) Google Official Blog (June 3, 2014) New York Times (July 16, 2014) Reasonable Expectation of Privacy? 24
29 Lost and Stolen Devices: Considering the high frequency of lost assets, encryption is as close to a no-brainer solution as it gets for this incident pattern. Sure, the asset is still missing, but at least it will save a lot of worry, embarrassment, and potential lawsuits by simply being able to say the information within it was protected. Competent and Reasonable Measures 25
30 Learning from the Past? 5/06 Dept. of Veterans Affairs (laptop & hard drive stolen from employee s home in burglary) 6/06 OMB (encrypt all sensitive data on agency mobile computers/devices) NV Encryption Law (eff. 10/1/08) MA Security Law (eff. 1/1/09) (encrypt PII on laptops and portable media) 8/11 Baltimore law firm (external hard drive backup left on light rail) 8/14 GA law firm (external hard drive backup - stolen from employee s trunk) 26
31 Bottom Line Encryption is increasingly required in areas like banking and health care and by new state data protection laws. As these requirements continue to increase, it will become more and more difficult for attorneys to justify avoidance of encryption. It has now reached the point where all attorneys should generally understand encryption, have it available for use when appropriate, and make informed decisions about when encryption should be used and when it is acceptable to avoid it. 27
32 Protect Decryption Key! Generally requires password/passphrase to access. Use a strong password/phrase - 12 characters or more. Use a password manager for multiple encryption instances. 28
33 Safeguards Backup Data Backup Recovery Key Enterprise Management Data 29
34 Strong Passwords / Passphrases Current recommendations for strong passwords or passphrases: Minimum length of 8 characters moving toward Contain lower and upper case letters Include number(s) Include symbol(s) Avoid dictionary words 30
35 Passphrases Iluvmy2005BMW! IluvmXy2005B3MW! Stronger: Break dictionary words with random letters, numbers, or symbols. 31
36 Laptops and Desktops Full Disk Encryption Limited Encryption Partition, Folder or File 32
37 Hardware Full Disk Encryption Automatically encrypts entire disk Decrypted access when an authorized user logs in Examples: Seagate Momentus (SED) Samsung SSD Hitachi Self-Encrypting Drive Seagate 33
38 Operating System Encryption Microsoft Windows - Bitlocker (business versions: Vista, 7, 8) [Encrypted File System (EFS)] Device Encryption (8.1 with specific tech specs) Apple OS X FileVault FileVault 2 34
39 Encryption Software Full Disk & Limited Examples: Check Point Dell Data Protection McAfee Endpoint Sophos Symantec (PGP and Endpoint) WinMagic TrueCrypt (open source) Encryption 35
40 Encrypted Portable Media CMS Secure Vault SanDisk Ironkey (Imation) Imation Bitlocker to Go Seagate Go-Flex 36
41 Smartphones and Tablets BlackBerry iphones and ipads Android 1. Follow manufacturer s instructions. 2. Enable encryption. 3. Use strong PIN or passcode. 4. Set auto timeout. 5. Use 3 rd party encryption on older Androids. 37
42 Proceed With Caution! 38
43 More Secure (Examples) Dell Data Protection Cloud Edition Sookasa Business Enterprise HP 39
44 Cloud Encryption Who has the key? Internet End User Cloud Service Provider 40
45 Wireless Networks [Wired Equivalent Privacy (WEP)] weak! Wi-Fi Protected Access (WPA) - cracked Wi-Fi Protected Access, second generation (WPA2) Sniffer programs War driving Pineapple Evil twin Source: Wikipedia.org 41
46 Wireless Networks 42
47 Let s Be Careful Out There! Risky if open (no need for username and password) Be sure you have a secure connection (https: or VPN) Be sure you have a properly configured firewall Warnings from security professionals / US-CERT Sgt. Phillip Freemason Esterhouse Hill Street Blues 43
48 Virtual Private Network VPN Concentrator Internal Network Internet VPN Remote User 44
49 IPv4 & IPv6 IPv6 traffic leaks DNS hijacking IPv6 routing tables Tunnel DNS requests VPN Data Leaks 45
50 Secure Connection ( Web Server (SSL / TLS) Internal Network Internet Encrypted Tunnel Remote User https: 46
51 Encryption Public Private 47
52 48
53 Digitally Signed
54 Signed and Encrypted Public 50
55 Outlook
56 Outlook
57 Gateway to Gateway (TLS) Server Server 2 1 Clear Clear 3 Encrypted 53
58 Secure Portal (Pull) Secure Portal 1 2 Notice of Message 3 54
59 Secure Attachment (Push) Internet Attachment Encrypted Attachment Clear 55
60 Secure (Examples) AppRiver DataMotion HP Secur (Voltage) Mimecast Office 365 Zixcorp 56
61 Law Practice Magazine (March-April 2015) 57
62 Encryption of Attachments Microsoft Office Adobe Acrobat WinZip Limited Protection! 58
63 Word Menu 1 59
64 2 3 Word 4 60
65 Microsoft Office
66 Adobe Acrobat 1 62
67 Adobe Acrobat 63
68 Adobe Acrobat 64
69 WinZip New File Existing File 65
70 Encryption is part of the solution. Use with other comprehensive security measures. BACKUP! Key recovery Enterprise management 66
71 ABA TECHSHOW Summer Series August 27, 2015
72 SAVE THE DATE! March 17-19,
73 2
74 Decrypting Encryption Gaining Competence on Encryption for Your Practice 1 Dave Ries Clark Hill PLC John Simek Sensei Enterprises, Inc. February 2015 Contents Encryption Overview... 2 Laptops and Portable Media... 6 Smartphones and Tablets Encryption: A Security No-Brainer Wireless Networks Conclusion An Encryption Quick Start Action Plan Encryption is a topic that most attorneys don t want to touch with a ten foot pole, but it is becoming a more and more important part of security. Encryption is an electronic process to protect data. It has now reached the point where all attorneys should generally understand encryption, have it available for use when appropriate, and make informed decisions about when encryption should be used and when it is acceptable to avoid it. Fortunately, easy to use options are available today for encryption. Most attorneys will need technical assistance to install and set up encryption, but it s generally easy from there. Encryption Overview Encryption is the conversion of data from a readable form, called plaintext, into a form, called ciphertext that cannot be easily understood by unauthorized people. Decryption is the process of converting encrypted data back into its original form (plaintext), so it can be understood. 1 Adapted from David G. Ries and John W. Simek, Encryption Made Simple for Lawyers, GPSolo Magazine (November/December 2012). Decrypting Encryption Page 2 of 17 April 16, 2015
75 Encryption can protect stored data (on servers, desktops, laptops, tablets, smartphones, portable devices, etc.) and transmitted data (over wired and wireless networks, including the Internet and e mail). Encryption uses a mathematical formula to convert the readable plaintext into unreadable ciphertext. The mathematical formula is an algorithm (called a cipher). Decryption is the reverse process that uses the same algorithm to transform the unreadable ciphertext back to readable plaintext. The algorithms are built into encryption programs users don t have to deal with them when they are using encryption. This graphic shows the basic steps: Encryption keys are used to implement encryption for a specific user or users. A key generator that works with the selected encryption algorithm is used to generate a unique key or keys for the user(s). A key is just a line or set of data that is used with the algorithm to encrypt and decrypt the data. Protection is provided by use of the algorithm with the unique key or keys. The process is called secret key or symmetric key encryption where the same key is used with an algorithm to both encrypt and decrypt the data. With secret key encryption, it is critical to protect the security of the key because it can be used by anyone with access to it to decrypt the data. Where a key pair is used, one to encrypt the data and a second one to decrypt the data, the process is called asymmetric encryption. For this kind of encryption, a key generator is used to generate a unique key pair, one for encryption (a public key) and the other for decryption (a private key). With key pairs, it is critical to protect the private decryption key since anyone with access to it can decrypt the data. Here is an example of a secret key for a commonly used algorithm called the Advanced Encryption Standard 256 (AES 256) algorithm. The same key is used to both encrypt and decrypt the data. +30NbBBMy7+1BumpfmN8QPHrwQr36/vBvaFLgQM561Q= Example AES 256 Key Let s look at a simple example of its application. A short line of readable plaintext, This is an encryption demo, becomes unreadable ciphertext when this key is used with the algorithm in an encryption program. Decrypting Encryption April 16, 2015 Page 3 of 17
76 Simple Example of Encryption The same key must be used with the algorithm in an encryption program to convert the ciphertextt back to readable plaintext. Simple Example of Decryption Symmetric key encryption is frequently used to protect data stored on servers, laptops, portable media, etc. The key is frequently used and stored on a single computer or mobile device where providing the key to someone at a remote location is not necessary. It is difficult to use symmetric key encryption for communications because it is a challenge to securely share the key with the recipient. Fortunately, users don t have to deal with keys during everyday use of encryption. When they log on with the correct password or passphrase, the program automatically accesses the key to decrypt the data. When they log off or shut down, the dataa is automatically encrypted. The following is a longer example a draft of an article written by the authors. A single key is used to encrypt the article. The same key is necessary to convert it back to plaintext. Decrypting Encryption Page 4 of 17 April 16, 2015
77 Here s an enlarged view of the plaintext and ciphertext: Enlarged Example: Symmetric Key Encryption Decrypting Encryption April 16, 2015 Page 5 of 17
78 Asymmetric encryption uses a key pair instead of a single key one key ( a public key) is used to encrypt the data and a second one (a private key) is used to decryptt the data. Key pairs are frequently used for encrypted communications. The sender uses the recipient s public encryption key to encrypt the communication. The public key cannot decrypt it; only thee decryption key can do that. The recipient uses the decryption (private key) to decrypt the data. Graphically, the process works this way: This is a brief overview of symmetric and asymmetric encryption and how it works. Attorneys do not have to understand the details. After encryption has been set up, it s generally automatic or point and click. Attorneys have ethical and common law duties to protect information relating to clients and often also have contractual and regulatory duties. The Ethics 20/20 updates to ABA Model Rules 1.1 and 1.6 made explicit attorneys duty to take competent and reasonable measures to safeguard information relating to clients. Encryption is an important consideration in addressing these duties. Laptops and Portable Media Example of Public Key Encryption The attributes that make laptops and portable devices useful also make them very dangerous from a security perspective: They re compact and portable. Add to that the fact that their costs have been decreasing over the years, their capacities have been dramatically increasing, and they have become more and more compact. Laptops are available with 2 TB (terabyte) and larger hard drives. USB thumb drives with capacities of 1 TB or more are now available. Portable hard drives of 1 TB or more are now Decrypting Encryption Page 6 of 17 April 16, 2015
79 available. A massive amount of data, in compact media, can be easily lost or stolen. With these devices, attorneys and employees can lose or steal the equivalent of a truckload of paper pages or more. Not properly protected, laptops and portable media can be recipes for a security disaster. One survey reported that 70 percent of data breaches resulted from the loss or theft of off network equipment (laptops, portable drives, PDAs, and USB drives). Strong security is a must. Encryption is now a standard security measure for protecting laptops and portable devices and attorneys should be using it. In fact, a joint U.S./UK research team has written that full disk encryption is so effective that law enforcement and federal agencies are complaining that they are unable to retrieve encrypted data in criminal investigations. Federal courts are struggling with the issue of whether compelled disclosure of passwords and pass phrases for decryption is prohibited by the Fifth Amendment. Most recently, British Prime Minister David Cameron and FBI Director James Comey have called for legally required backdoors to encryption for national security and law enforcement. After the high profile theft from an employee s home of a Department of Veterans Affairs laptop and external hard drive containing personal information on more than 28 million veterans in 2006, security guidelines for federal agencies added the requirement of encryption of all data on laptops and portable devices, unless it is classified as non sensitive. This was almost nine years ago. In January 2007, 18 laptops were stolen from the offices of a law firm in Orlando, Florida. The laptops were reportedly protected by encryption, and the incident received very little publicity. In discussing this incident, the SANS Institute, a leading information security organization, noted, [l]aptop thefts aren t going away, but by this time next year, this type of item (laptop stolen, but the data was protected) shouldn t be newsworthy. That was more than eight years ago. In one data breach report, a Maryland law firm lost an unencrypted portable hard drive that contained medical records of patients in a lawsuit against its client hospital. One of the law firm s employees took the hard drive containing backup data home with her. This was the firm s method of ensuring that it had an off site backup. She took the light rail system home and left the drive on the train. When she came back a few minutes later, it was gone. Backup is a good practice, but not if it s done in a way that exposes confidential data. If the drive had been encrypted, it would have had a strong level of protection. As it was, it had little or none. It is not uncommon for backup software to have the ability to encrypt the backed up information. Generally, it is just a simple matter to check an option for the backup to be encrypted. In a recent example, an external hard drive was stolen from the trunk of the car of an employee of an Atlanta law firm. It contained confidential information about clients. It was not encrypted. As these examples demonstrate, encryption is particularly important for laptops and portable media. A lost or stolen laptop or portable device that is encrypted is protected unless the decryption key has been compromised. Decrypting Encryption April 16, 2015 Page 7 of 17
80 Encryption basics. There are two basic approaches to encrypting data on hard drives: full disk encryption and limited encryption. As its name suggests, full disk encryption protects the entire hard drive. It automatically encrypts everything and provides decrypted access when an authorized user properly logs in. Limited encryption protects only specified files or folders or a part of the drive. With limited encryption, the user has to elect to encrypt the specific data. There are also three kinds of encryption for protecting laptops and portable devices: hardware encryption, encryption in operating systems (such as Windows and Apple OS X), and encryption software. Hardware full disk encryption. All hard drive manufacturers now offer drives with hardware full disk encryption built in. The major laptop manufacturers all offer models with these drives. Hardware encryption is generally easier to use and administer than encryption software. Some examples are Seagate Secure ( and Hitachi Self Encrypting Drives ( Secure use simply requires enabling encryption and setting a strong password or pass phrase. The contents of the drive are automatically decrypted when an authorized user logs in. It is automatically encrypted when the user logs off or the laptop is turned off. Because most encryption programs are tied to a user s password, secure passwords or pass phrases are essential, and a forgotten password can lead to lost data. Automatic logoff, after a specified time, is critical so that unencrypted data will not be exposed if a user goes away from a computer or forgets to turn it off. In an enterprise environment, like a law firm, access by an administrator, ability to reset passwords, backup, and key recovery are essential. Installing encryption and administering it, particularly in a large enterprise, can be a challenge. Encryption in operating systems. Current business versions of Windows and current versions of Apple OS X have built in encryption capability. Windows Vista Enterprise and Ultimate and Windows 7 Enterprise and Ultimate, and Windows 8 and 8.1 Professional and Enterprise include an encryption feature called BitLocker. BitLocker works below the Windows operating system and encrypts an entire volume on the hard drive. This means that when the drive is encrypted, the encryption protects the operating system, as well as all software and data on the drive. For versions of Windows that do not support BitLocker, software encryption, discussed below, can be used. On versions before Windows 8.1, BitLocker required either a computer that is equipped with a Trusted Platform Module (TPM) chip or use of an external USB drive to hold the decryption key. A TPM module is a security chip on the computer s motherboard that supports encryption. If a user plans to use BitLocker on a computer, it is important to select one that has a TPM chip the meets the current specification. Check the hardware requirements for the version of Windows that you are using and compare it with the specifications for the desktop or laptop. Or ask someone for advice the major PC manufacturers have chat features on their websites to answer questions about their products. Use of a Decrypting Encryption April 16, 2015 Page 8 of 17
81 key on a USB drive is less secure because encryption can be defeated if an intruder gains access to the USB key. With Windows 8.1, there s another alternative for BitLocker with computers that don t have a TPM chip. It can be set up directly on the computer, but it requires a pre boot passphrase that accesses the decryption key. This means that a user has to enter a pre boot passphrase, then log into Windows. A user can set up the same passphrase for both, but it has to be entered twice, once for pre boot and once for logging in. The business versions of Windows also include an encryption function called Encrypting File System (EFS). It allows encryption of files and folders. An authorized user who is logged in has access to decrypted data. It is encrypted and unreadable to anyone else (unless they can defeat the login process). EFS is considered a fairly weak encryption method that is easily cracked using forensic tools. You are better off using BitLocker or one of the other third party encryption products discussed below. Setup of both EFS and BitLocker is fairly technical. For most attorneys, it will be necessary to obtain technical assistance to implement them. OS X has built in file encryption in FileVault. Newer versions have full disk encryption available in FileVault 2. Follow Apple s instructions for turning it on. After a password is set, it just requires turning on the FileVault button in System Preferences. Recent advances have attacked Apple s encryption scheme, and the Passware software suite claims to be able to defeat FileVault 2 in less than an hour. Third party encryption software. Some commonly used third party encryption software products for hard drives include those offered by Symantec (PGP and Endpoint; McAfee (Endpoint Encryption; Check Point (ZoneAlarm DataLock; ( WinMagic (SecureDoc; and Sophos (SafeGuard; These vendors all have options available for Macs. Portable Drives. Hardware encrypted drives and encryption software are available for USB drives and portable hard drives. Microsoft s BitLocker to Go can be used to encrypt portable devices. Individual USB drives with built in encryption capability are also available, such as the IronKey ( Kanguru Micro ( Kingston ( and SanDisk Cruzer Professional and Cruzer Enterprise ( The IronKey is a favorite of the authors. It includes strong encryption, wiping if the wrong credentials are entered too many times, and has strong physical construction. As an added bonus, several of the models contain a password management application called Identity Manager, which stores all your 14+ character passwords in a secured, encrypted vault. Of course you can store any length password, but the current recommendation is 14 or more characters. To avoid the loss of data, it is important to understand how the encryption works, to back up data that is encrypted, and to keep a copy of the recovery key in a secure place. Enterprise controls are available to centrally manage encryption in law firms and other enterprises. Decrypting Encryption April 16, 2015 Page 9 of 17
82 Smartphones and Tablets Smartphones and tablets are basically small computers, with substantial computing power and high storage capacity. Like laptops and other mobile devices, they can be easily lost or stolen and should be protected with encryption. BlackBerry devices ( have long been the gold standard for security, although its market share has substantially declined. If you use the BlackBerry Enterprise Server (BES), the communications are automatically encrypted. Encrypting the device itself is accomplished by enabling Content Protection. You can find that choice by navigating to Options > Security Options > Encryption. This is where you will set encryption for the device memory, encryption strength, contacts, media files, and expansion memory card. In addition, you will need to set a password for the phone as well as the inactivity timer to lock the phone. The password and time outs are set by going to Options > Password. A lot of law firms use BES to manage their BlackBerry devices. This centralized management will push the desired security settings to the phones with no user interaction. For iphones and ipads ( hardware encryption was implemented in ios 4. All files are automatically encrypted when the iphone or ipad is lock coded and decrypted when the device is unlocked. It provides limited protection unless Simple Passcode is turned off, Require Passcode is turned on, and a strong pass code is selected. Require Passcode should be set for a short time and Erase Data should be turned on. ios also includes a feature called Data Protection. It secures e mails and attachments stored on the device and data in other apps that are designed to work with it. Android OS ( has included encryption for tablets (starting with Honeycomb) and for phones (starting with Ice Cream Sandwich). Earlier versions require third party apps for encryption, such as WhisperCore (whispersys.com), Droid Crypt (tinyurl.com/9m3d598), or AnDisk Encryption (tinyurl.com/8no7qsh). Also, Motorola ( and Samsung ( market enterprise phones with built in encryption capability. Follow the device manufacturer s instructions for turning on encryption. It generally requires touching the Encrypt or Encrypt Tablet button in Settings. A strong PIN or password and automatic logoff after a set time are also important to keep the data encrypted. Like the iphone, the device is automatically be encrypted when it is locked and decrypted when it is unlocked. Starting with Android Lollipop (released at the end of 2014), Android encryption will automatically be enabled when a PIN, password, or swipe pattern is set. Again, it is important to follow the manufacturer s instructions when setting up encryption. Get help if you need it. First time encryption takes some time when a device has already been in use, so make sure that the battery is fully charged before starting or better yet, have the charger connected. Weaknesses have been reported in the encryption for both ios and Android, so it is important to consider multiple levels of security. Despite some limitations, smartphones and tablets are more secure with encryption, and attorneys should be using it. Decrypting Encryption April 16, 2015 Page 10 of 17
83 It is also important to make sure that secure methods are used for getting files on and off smartphones and tablets and for sharing files. There is substantial concern about the security of consumer services such as Dropbox ( and icloud ( Their terms of use provide limited protection and they control the encryption so their employees can get access, and protection from unauthorized third parties depends on how well they protect the decryption keys. Use of alternatives such as business versions of Box ( or SpiderOak ( using add on end user encryption like BoxCryptor ( Viivo ( and Dell Data Protection Cloud Edition ( with services like Dropbox provides stronger security because the end user controls the decryption keys. It should be noted that Dropbox has been adding security capability to its business offerings and may be a viable option after they have been fully implemented and evaluated. Encryption: A Security No Brainer Encryption is particularly important for laptops, smartphones, tablets, and portable media because they can easily be lost or stolen. The Verizon 2014 Data Breach Investigation Report, which covers 2013, explains the risk and a solution to it encryption this way: 2 PHYSICAL THEFT AND LOSS RECOMMENDED CONTROLS The primary root cause of incidents in this pattern is carelessness of one degree or another. Accidents happen. People lose stuff. People steal stuff. And that s never going to change. But there are a few things you can do to mitigate that risk. Encrypt devices Considering the high frequency of lost assets, encryption is as close to a no-brainer solution as it gets for this incident pattern. Sure, the asset is still missing, but at least it will save a lot of worry, embarrassment, and potential lawsuits by simply being able to say the information within it was protected. (Emphasis added.) It s not just Verizon; this view is widely held by information security professionals and government agencies. 3 Encryption can protect all of the mobile technology used by attorneys, including smartphones, tablets, laptops, mobile devices and portable storage (e.g., external hard drives, USB drives, DVDs and CDs) E.g., US CERT, the National Institute of Science and Technology (NIST), the Federal Communications Commission, and the Department of Health and Human Services have all recommended or required encryption on mobile devices to protect confidential information. Decrypting Encryption April 16, 2015 Page 11 of 17
84 Encryption solutions for mobile devices are readily available, inexpensive, and generally easy to set up and use. Wireless Networks Communication via wireless connections needs to be secured as well in order to protect the transmission. Encrypting the wireless network will protect the data from being intercepted and viewed. There are many free sniffer applications that can be used to view the contents of unencrypted data streams. Essentially, there are three commonly available types of encryption schemes for your wireless network: WEP (Wired Equivalent Privacy), WPA (Wi Fi Protected Access), and WPA2 (second generation WPA). These encryption methods can be used on all currently available wireless access points. WEP is very weak encryption and is fairly easy to crack. There are plenty of free tools available that can crack WEP in a matter of minutes. WEP should not be used in any wireless network because of its insecurity. WPA is a stronger form of encryption, but it has also been cracked. Therefore, WPA is not recommended either. WPA2 is secure and should be the encryption method of choice for wireless networks. As with other forms of password management, the WPA2 pass phrase should be long and complex. In addition to making sure that their wireless networks are secure, attorneys should ensure that thirdparty wireless networks that they use for client matters are protected by encryption. They should be protected by WPA2 as well and require a user name and password for access. This is particularly the case for public networks. Many security professionals and US CERT (United States Computer Emergency Readiness Team) have recommended that public networks should not be used for confidential communications. If public networks are to be used, attorneys should obtain technical assurance that they are being securely used through protection such as a secure (https) connection to a trusted website or a virtual private network (VPN). A recent ethics opinion concluded that an attorney has an ethical duty to evaluate the security of a wireless network, home or public, before it is used for client communications and to take appropriate precautions in using it. California Formal Opinion No E mail Particularly important to attorneys is the confidentiality and integrity of e mails. Respected security professionals have for years compared e mail to postcards or to postcards written in pencil. They can be viewed or altered by third parties. While some ethics opinions have been incorrectly interpreted as saying that e mail encryption is never required, current ethics opinions continue to stress the requirement of reasonable and competent safeguards. For example, California Formal Opinion No states, encrypting may be a reasonable step for an attorney to take in an effort to ensure the confidentiality of such communications remain so when circumstance calls for it, particularly if the information at issue is highly sensitive and the use of encryption is not onerous. Encryption is increasingly required in areas such as banking and health care and by new state data protection laws. As Decrypting Encryption April 16, 2015 Page 12 of 17
85 these requirements continue to increase, it will become more and more difficult for attorneys to justify their avoidance of encryption. For e mail, the term encryption is generally used to mean both encryption and the authentication process that are used, in combination, to protect e mail. Encryption protects the confidentiality of e mail. Authentication identifies the sender of an e mail and verifies its integrity. Encryption is a process that translates a message into protected electronic code. The recipient (or anyone intercepting the message) must have a key to decrypt it and make it readable. Although it still takes some technical knowledge to set up, e mail encryption is now easier to use than it once was. Encryption generally uses a pair of keys to encrypt the e mail. The sender uses the recipient s public key to encrypt the e mail and any attachments. Because the public key only encrypts the e mail, it does not matter that it is available to the public or to various senders. The recipient then uses his or her private key to decrypt the e mail. It needs to be safeguarded because anyone who has access to the private key can use it for decryption. The process is easy to use once the keys are set up in an e mail program such as Outlook ( The most difficult process is getting the keys (digital IDs) and making the public key available to senders. Once it is set up in Outlook, the sender just has to click on the Message tab in the Options group and click the Encrypt Message Contents and Attachments button. At the recipient s end, the message will automatically be decrypted if his or her private key has been installed. Digital authentication of e mail also generally uses a key pair. The sender uses his or her private key to digitally sign the e mail. The recipient then uses the sender s public key to verify the sender and integrity of the message. In Outlook, after installation of the private key, the sender clicks the Options tab in the Permission group and clicks Sign Message. After the sender s public key has been installed in the recipient s compatible e mail program, the recipient will receive an automatic notice of verification of the sender and integrity. For protection of confidentiality and authentication, the sender s and recipient s key pairs are used in combination. The sender uses both the Encrypt Message and Attachments command button (that uses the recipient s private key) and the Sign Message command (that uses the sender s private key). At the receiving end, the e mail program automatically uses the recipient s private key to decrypt the messages and automatically uses the sender s public key to verify authenticity and integrity. Again, the challenging part is obtaining key pairs, exchanging public keys, and setting them up in the e mail program for encryption. Keys are available from commercial public key authorities such as Verisign (now part of Symantec; Public key authorities have online directories where their customers public keys are available. The management and exchange of keys is a major reason why attorneys do not encrypt e mail. Instead, they are more likely to use an encryption service that provides encrypted e mail delivery without key exchange. Decrypting Encryption April 16, 2015 Page 13 of 17
86 Another form of e mail encryption is Transport Layer Security (TLS) encryption. It automatically encrypts e mail between two e mail gateways. If a law firm and client each have their own e mail gateways, TLS can be used to encrypt automatically all e mails between them. TLS encryption protects e mails between e mail gateways only. It does not protect e mails within the sender s and recipient s networks and does not protect e mail that is misaddressed or forwarded through other e mail gateways. Secure e mail is also available from managed messaging service providers such as Zixcorp ( Mimecast ( and DataMotion ( They provide e mail encryption without the complexity of setting up and exchanging keys. As an alternative to e mail, confidential information can be exchanged by using secure file sharing and transfer options such Biscom ( or Accellion ( or by using add on encryption (e.g., BoxCryptor or Viivo with Dropbox or another cloud vendor). Another alternative to encryption of e mail is to give confidential information a basic level of protection by putting it in a password protected attachment rather than in the body of the e mail. File password protection in some software, such as current versions of Microsoft Office, Adobe Acrobat ( and WinZip ( uses encryption to provide security. It encrypts only the document and not the e mail, so the confidential information should be limited to the attachment. It is generally easier to use than complete encryption of e mail and attachments. However, the protection can be limited by the use of weak passwords that are easy to break or crack. In addition, it should be obvious not to include the password for the attachment in the body of the e mail message. Electronic communications have now reached the point that most attorneys should have encryption available for use in appropriate circumstances. In addition to complying with any legal requirements that apply, the most prudent approach to the ethical duty of protecting confidentiality of electronic communications is to have an express understanding with clients about the nature of communications that will be (and will not be) sent by e mail and whether or not encryption and other security measures will be utilized. Conclusion Encryption is now a generally accepted practice in information security for protection of confidential data. Attorneys should understand encryption and use it in appropriate situations. All attorneys should use encryption on laptops, portable storage media, smartphones, and tablets that contain information relating to clients. They should make sure that transmissions over wireless networks are secure. Attorneys should have encryption available for e mail or secure file transfer and use it when appropriate. Although most attorneys will need technical assistance to install and set up encryption, use of encryption after that is generally easy. Decrypting Encryption April 16, 2015 Page 14 of 17
87 David G. Ries is a member of Clark Hill, PLC, in Pittsburgh, Pennsylvania. John W. Simek ([email protected]) is Vice President of Sensei Enterprises, Inc., a legal technology, information security, and digital forensics firm in Fairfax, Virginia. They are co authors, with Sharon D. Nelson, of Encryption Made Simple for Lawyers (Americann Bar Association 2015) and Locked Down: Information Security for Attorneys (American Bar Association 2012). Decrypting Encryption Page 15 of 17 April 16, 2015
88 An Encryption Quick Start Action Plan This Quick Start Action Plan is from Encryption Made Simple for Lawyers (American Bar Association 2015). References to Chapters are to the book. An American Bar Association resolution adopted in August 2014 encourages private and public sector organizations to develop, implement, and maintain an appropriate cybersecurity program that complies with applicable ethical and legal obligations, and is tailored to the nature and scope of the organization, and the data and systems to be protected. It covers attorneys and law firms, as well as other businesses and enterprises. An appropriate information security or cybersecurity program is an essential part of compliance with attorneys duty under ABA Model Rule 1.6(c) to employ reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. Encryption of data is a critical component of an appropriate information security or cybersecurity program. (Chapters 2 and 3) This Quick Start Action Plan outlines the steps that attorneys can take to implement encryption starting now. 1. Start with the basics for encryption that you are using now or implementing in the future. (Chapter 5) a. If you need help in implementing encryption, find someone who is qualified to assist you. b. Protect encrypted data with strong authentication. In many implementations of encryption, access to the decryption key is protected by the user s password or passphrase. Make sure that you have strong passwords or passphrases for encryption you are currently using or you plan to implement in the future. c. Back up data. Like other areas of technology, there can be technical failures with encryption hardware and software. Keep a secure backup of encrypted data, a step that should always be done, even for data that is not encrypted. d. Back up the recovery keys. In some implementations of encryption, a user can back up a recovery key that may make encrypted data recoverable if a user forgets a password or there is a technology problem. Back up the recovery key in a secure place. In mid sized and larger firms, recovery keys should be managed by IT staff. 2. Start with the no brainer encryption solutions encryption of laptops, smartphones, tablets, and portable drives. (Chapters 5, 6 and 7) The Verizon 2014 Data Breach Investigation Report notes that encryption is as close to a no brainer solution as it gets to protect confidential data on lost or stolen laptops and mobile devices. It s not just Verizon, this view is widely held by information security professionals and government agencies. Review the devices that you and your firm are using laptops, smartphones, tablets, and portable drives and make plans to encrypt them as soon as Decrypting Encryption April 16, 2015 Page 16 of 17
89 reasonably possible if they are not already encrypted. With many of them, it s just a matter of turning encryption on. Consider encryption and enable it when you add new devices. 3. Protect confidential documents with encryption a solution you already have. (Chapter 11) Confidential documents transmitted electronically or by e mail should be protected by encryption. Current versions of Microsoft Office, Adobe Acrobat and WinZip encrypt documents when password protection is used. New Jersey Ethics Opinion 701 (April 2006 over eight years ago) advised attorneys to password protect documents [encrypt them] when they are sent over the Internet. (Chapter 2.) While this form of encryption may not be as secure as some of the other solutions discussed in the book, it is much more secure than no encryption and is immediately available to most attorneys. 4. Use secure network connections. (Chapter 8) Confidential data that is transmitted outside of a secure network should be protected. This requires secure connections between networks and over the Internet. Review the various network connections that you and your firm use and make sure that they are secure. For the Internet, you should use or virtual private networks as a minimum. 5. Secure your wireless networks. (Chapter 8.) Make sure that your law office wireless network and home networks used for client data are protected by WPA2 (Wi Fi Protected Access 2) encryption and are securely configured. If you are using an older wireless access device that does not support WPA2, replace it. 6. Be careful on public networks. (Chapter 8) Make sure that you can use a public network securely for confidential data before you use it, or avoid using it. Use only secure connections or a virtual private network. 7. Implement an encrypted e mail solution. (Chapter 9) It has now reached the point where most or all attorneys should have the ability to use encrypted e mail, where appropriate, for confidential communications. A basic level of protection can be provided by putting the confidential communication in a password protected/encrypted attachment. There are now a number of easy to use, inexpensive options that are available for securing e mail, including ones for solos and small firms. 8. Use encryption in the cloud. (Chapter 10) Encryption controlled by the end user should be the default for confidential data stored in the cloud. End user controlled encryption should be required for attorneys unless the attorney makes an informed decision that the data is not sensitive enough to require this level of protection or that the cloud service provider will implement and maintain sufficient security controls without end user controlled encryption. For attorneys, this requires the analysis required by the ethics rules and opinions discussed in Chapter 2, including competent and reasonable measures to safeguard information relating to clients, due diligence concerning service providers, and requiring service providers to safeguard data in accordance with attorneys confidentiality obligations. Decrypting Encryption April 16, 2015 Page 17 of 17
Encryption Made Simple for Lawyers
Encryption Made Simple for Lawyers By David G. Ries, Esq. and John W. Simek Encryption is a topic that most attorneys don t want to touch with a 10-foot pole, but it is becoming a more and more important
Keeping Data Safe. Patients, Research Subjects, and You
Keeping Data Safe Patients, Research Subjects, and You How do hackers access a system Hackers Lurking in Vents and Soda Machines By NICOLE PERLROTH APRIL 7, 2014 New York Times SAN FRANCISCO They came
Mobile Security & Cybersecurity Issues for Physicians & Patients Across the Care Continuum
Mobile Security & Cybersecurity Issues for Physicians & Patients Across the Care Continuum 8th Annual NJ/DV Conference: IT - The Politics of Healthcare October 29, 2015 Atlantic City, NJ William Buddy
Research Information Security Guideline
Research Information Security Guideline Introduction This document provides general information security guidelines when working with research data. The items in this guideline are divided into two different
Guidelines on use of encryption to protect person identifiable and sensitive information
Guidelines on use of encryption to protect person identifiable and sensitive information 1. Introduction David Nicholson, NHS Chief Executive, has directed that there should be no transfers of unencrypted
Department of Veterans Affairs Two-Factor Authentication MobilePASS Quick Start Guide November 18, 2015
Department of Veterans Affairs Two-Factor Authentication Quick Start Guide November 18, 2015 Introduction: This guide provides instructions for installation of the soft token on your non-piv enabled or
Ensuring the security of your mobile business intelligence
IBM Software Business Analytics Cognos Business Intelligence Ensuring the security of your mobile business intelligence 2 Ensuring the security of your mobile business intelligence Contents 2 Executive
Mobile Iron User Guide
2015 Mobile Iron User Guide Information technology Sparrow Health System 9/1/2015 Contents...0 Introduction...2 Changes to your Mobile Device...2 Self Service Portal...3 Registering your new device...4
FileCloud Security FAQ
is currently used by many large organizations including banks, health care organizations, educational institutions and government agencies. Thousands of organizations rely on File- Cloud for their file
Pryvate App User Manual
Pryvate App User Manual 2.0 Powered by Criptyque Pryvate is the most secure voice, email & chat app for business people & individuals that require a high level of communications encryption to protect their
Spring Hill State Bank Mobile Banking FAQs
Spring Hill State Bank Mobile Banking FAQs What is Mobile Banking? Mobile Banking enables you to access your account information using the Bank online banking website. You must first be enrolled as an
Security Guide. BlackBerry Enterprise Service 12. for ios, Android, and Windows Phone. Version 12.0
Security Guide BlackBerry Enterprise Service 12 for ios, Android, and Windows Phone Version 12.0 Published: 2015-02-06 SWD-20150206130210406 Contents About this guide... 6 What is BES12?... 7 Key features
BlackBerry 10.3 Work and Personal Corporate
GOV.UK Guidance BlackBerry 10.3 Work and Personal Corporate Published Contents 1. Usage scenario 2. Summary of platform security 3. How the platform can best satisfy the security recommendations 4. Network
Information Security It s Everyone s Responsibility
Information Security It s Everyone s Responsibility Developed By The University of Texas at Dallas (ISO) Purpose of Training As an employee, you are often the first line of defense protecting valuable
Information Security It s Everyone s Responsibility
Information Security It s Everyone s Responsibility The University of Texas at Dallas Information Security Office (ISO) Purpose of Training Information generated, used, and/or owned by UTD has value. Because
Using End User Device Encryption to Protect Sensitive Information
Using End User Device Encryption to Protect Sensitive Information April 29, 2015 Mel Jackob, CISSP, GSEC, eplace Solutions, Inc. William Ewy, CIPP/US, eplace Solutions, Inc. William Ewy, BSEE, CIPP/US
HELPFUL TIPS: MOBILE DEVICE SECURITY
HELPFUL TIPS: MOBILE DEVICE SECURITY Privacy tips for Public Bodies/Trustees using mobile devices This document is intended to provide general advice to organizations on how to protect personal information
Secure Email Client Guide
PRESIDIO BANK 33 Secure Email Client Guide THE BUSINESS BANK THAT WORKS 8/2013 Table of Contents Introduction.....3 Our Responsibility to Protect Confidential Information....4 Registering and Accessing
Last modified: November 22, 2013 This manual was updated for the TeamDrive Android client version 3.0.216
Last modified: November 22, 2013 This manual was updated for the TeamDrive Android client version 3.0.216 2013 TeamDrive Systems GmbH Page 1 Table of Contents 1 Starting TeamDrive for Android for the First
Deploying iphone and ipad Security Overview
Deploying iphone and ipad Security Overview ios, the operating system at the core of iphone and ipad, is built upon layers of security. This enables iphone and ipad to securely access corporate services
BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: 10.1.1. Security Note
BlackBerry Enterprise Service 10 Secure Work Space for ios and Android Version: 10.1.1 Security Note Published: 2013-06-21 SWD-20130621110651069 Contents 1 About this guide...4 2 What is BlackBerry Enterprise
Supplier Information Security Addendum for GE Restricted Data
Supplier Information Security Addendum for GE Restricted Data This Supplier Information Security Addendum lists the security controls that GE Suppliers are required to adopt when accessing, processing,
HP ProtectTools Embedded Security Guide
HP ProtectTools Embedded Security Guide Document Part Number: 364876-001 May 2004 This guide provides instructions for using the software that allows you to configure settings for the HP ProtectTools Embedded
USER MANUAL. v. 1.0.0.95 Windows Client ------------------------ January 2014 ------------------------
USER MANUAL v. 1.0.0.95 Windows Client ------------------------ January 2014 ------------------------ 1 Contents At a Glance Troubleshoot 3 About SkyCrypt 23 FAQ 4 About this manual 23 Contact support
Secure Email User Guide
Secure Email User Guide Transport Layer Security (TLS) Pretty Good Privacy (PGP) PDF Messenger 1 Contents 1 Introduction... 3 2 Transport Layer Security (TLS).4 3 Pretty Good Privacy (PGP).5 4 PDF Messenger...
iphone in Business How-To Setup Guide for Users
iphone in Business How-To Setup Guide for Users iphone is ready for business. It supports Microsoft Exchange ActiveSync, as well as standards-based services, delivering email, calendars, and contacts over
Remote Desktop Gateway. Accessing a Campus Managed Device (Windows Only) from home.
Remote Desktop Gateway Accessing a Campus Managed Device (Windows Only) from home. Contents Introduction... 2 Quick Reference... 2 Gateway Setup - Windows Desktop... 3 Gateway Setup Windows App... 4 Gateway
Whitepaper Enhancing BitLocker Deployment and Management with SimplySecure. Addressing the Concerns of the IT Professional Rob Weber February 2015
Whitepaper Enhancing BitLocker Deployment and Management with SimplySecure Addressing the Concerns of the IT Professional Rob Weber February 2015 Page 2 Table of Contents What is BitLocker?... 3 What is
Introduction. Purpose. Reference. Applicability. HIPAA Policy 7.1. Safeguards to Protect the Privacy of PHI
Office of Regulatory Compliance 13001 E. 17 th Place, Suite W1124 Mail Stop F497 Aurora, CO 80045 Main Office: 303-724-1010 Main Fax: 303-724-1019 HIPAA Policy 7.1 Title: Source: Prepared by: Approved
Cloud Services MDM. ios User Guide
Cloud Services MDM ios User Guide 10/24/2014 CONTENTS Overview... 3 Supported Devices... 3 System Capabilities... 3 Enrollment and Activation... 4 Download the Agent... 4 Enroll Your Device Using the Agent...
SUBJECT: Effective Date Policy Number Security of Mobile Computing, Data Storage, and Communication Devices
SUBJECT: Effective Date Policy Number Security of Mobile Computing, Data Storage, and Communication Devices 8-27-2015 4-007.1 Supersedes 4-007 Page Of 1 5 Responsible Authority Vice Provost for Information
Sophos Mobile Control User guide for Apple ios. Product version: 4
Sophos Mobile Control User guide for Apple ios Product version: 4 Document date: May 2014 Contents 1 About Sophos Mobile Control...3 2 About this guide...4 3 Login to the Self Service Portal...5 4 Set
Mobile Device Security and Encryption Standard and Guidelines
Mobile Device Security and Encryption Standard and Guidelines University Mobile Computing and Device best practices are currently defined as follows: 1) The use of any sensitive or private data on mobile
SOMITS is located in the 1648 Pierce Drive School of Medicine Building, Suite AB51.
School of Medicine Information Technology Services All newly enrolled School of Medicine students are encouraged to visit the School of Medicine s IT office before orientation to obtain help configuring
Ensuring HIPAA Compliance with AcclaimVault Online Backup and Archiving Services
Ensuring HIPAA Compliance with AcclaimVault Online Backup and Archiving Services 1 Contents 3 Introduction 5 The HIPAA Security Rule 7 HIPAA Compliance & AcclaimVault Backup 8 AcclaimVault Security and
iphone in Business Security Overview
iphone in Business Security Overview iphone can securely access corporate services and protect data on the device. It provides strong encryption for data in transmission, proven authentication methods
Securing Corporate Data and Making Life Easier for the IT Admin Benefits of Pre Boot Network Authentication Technology
20140115 Securing Corporate Data and Making Life Easier for the IT Admin Benefits of Pre Boot Network Authentication Technology TABLE OF CONTENTS What s at risk for your organization? 2 Is your business
Two Factor Authentication (TFA; 2FA) is a security process in which two methods of authentication are used to verify who you are.
Two Factor Authentication Two Factor Authentication (TFA; 2FA) is a security process in which two methods of authentication are used to verify who you are. For example, one method currently utilized within
BlackBerry Enterprise Service 10. Universal Device Service Version: 10.2. Administration Guide
BlackBerry Enterprise Service 10 Universal Service Version: 10.2 Administration Guide Published: 2015-02-24 SWD-20150223125016631 Contents 1 Introduction...9 About this guide...10 What is BlackBerry
Security Architecture Whitepaper
Security Architecture Whitepaper 2015 by Network2Share Pty Ltd. All rights reserved. 1 Table of Contents CloudFileSync Security 1 Introduction 1 Data Security 2 Local Encryption - Data on the local computer
Protecting your Data, Devices, and Digital Life in a BYOD World: A Security Primer GLENDA ROTVOLD AND SANDY BRAATHEN NBEA APRIL 2, 2015
Protecting your Data, Devices, and Digital Life in a BYOD World: A Security Primer GLENDA ROTVOLD AND SANDY BRAATHEN NBEA APRIL 2, 2015 What are You Trying to Protect? If someone got into your email, what
When enterprise mobility strategies are discussed, security is usually one of the first topics
Acronis 2002-2014 Introduction When enterprise mobility strategies are discussed, security is usually one of the first topics on the table. So it should come as no surprise that Acronis Access Advanced
Policy Based Encryption E. Administrator Guide
Policy Based Encryption E Administrator Guide Policy Based Encryption E Administrator Guide Documentation version: 1.2 Legal Notice Legal Notice Copyright 2012 Symantec Corporation. All rights reserved.
Policy Based Encryption E. Administrator Guide
Policy Based Encryption E Administrator Guide Policy Based Encryption E Administrator Guide Documentation version: 1.2 Legal Notice Legal Notice Copyright 2012 Symantec Corporation. All rights reserved.
Disk Encryption. Aaron Howard IT Security Office
Disk Encryption Aaron Howard IT Security Office Types of Disk Encryption? Folder Encryption Volume or Full Disk Encryption OS / Boot Volume Data Volume Managed or Unmanaged Key Backup and Data Assurance
Chapter 11 Security+ Guide to Network Security Fundamentals, Third Edition Basic Cryptography
Chapter 11 Security+ Guide to Network Security Fundamentals, Third Edition Basic Cryptography What Is Steganography? Steganography Process of hiding the existence of the data within another file Example:
ipad in Business Security
ipad in Business Security Device protection Strong passcodes Passcode expiration Passcode reuse history Maximum failed attempts Over-the-air passcode enforcement Progressive passcode timeout Data security
Recipe for Mobile Data Security: TPM, Bitlocker, Windows Vista and Active Directory
Recipe for Mobile Data Security: TPM, Bitlocker, Windows Vista and Active Directory Tom Olzak October 2007 If your business is like mine, laptops regularly disappear. Until recently, centrally managed
Sophos Mobile Control Administrator guide. Product version: 3
Sophos Mobile Control Administrator guide Product version: 3 Document date: January 2013 Contents 1 About Sophos Mobile Control...4 2 About the Sophos Mobile Control web console...7 3 Key steps for managing
Backing up your digital image collection provides it with essential protection.
Backing up your digital image collection provides it with essential protection. In this chapter, you ll learn more about your options for creating a reliable backup of your entire digital image library.
Chapter 3 Safeguarding Your Network
Chapter 3 Safeguarding Your Network The RangeMax NEXT Wireless Router WNR834B provides highly effective security features which are covered in detail in this chapter. This chapter includes: Choosing Appropriate
End User Devices Security Guidance: Apple ios 8
GOV.UK Guidance End User Devices Security Guidance: Apple ios 8 Published Contents 1. Changes since previous guidance 2. Usage scenario 3. Summary of platform security 4. How the platform can best satisfy
Using the Jive for ios App
Using the Jive for ios App TOC 2 Contents App Overview...3 System Requirements... 4 Release Notes...5 Which Version Am I Using?... 6 Connecting to Your Community... 11 Getting Started...12 Using Your Inbox...13
Data Protection Act 1998. Bring your own device (BYOD)
Data Protection Act 1998 Bring your own device (BYOD) Contents Introduction... 3 Overview... 3 What the DPA says... 3 What is BYOD?... 4 What are the risks?... 4 What are the benefits?... 5 What to consider?...
Security for mobile apps
November 2014 Security for mobile apps This white paper provides education on security considerations and requirements for mobile apps. 1 Contents Authentication & security for mobile apps 3 Securing mobile
Troubleshooting BlackBerry Enterprise Service 10 version 10.1.1 726-08745-123. Instructor Manual
Troubleshooting BlackBerry Enterprise Service 10 version 10.1.1 726-08745-123 Instructor Manual Published: 2013-07-02 SWD-20130702091645092 Contents Advance preparation...7 Required materials...7 Topics
Securing Patient Data in Today s Mobilized Healthcare Industry. A Good Technology Whitepaper
Securing Patient Data in Today s Mobilized Healthcare Industry Securing Patient Data in Today s Mobilized Healthcare Industry 866-7-BE-GOOD good.com 2 Contents Executive Summary The Role of Smartphones
Smart TPM. User's Manual. Rev. 1001 12MD-STPM-1001R
Smart TPM User's Manual Rev. 1001 12MD-STPM-1001R We recommend that you download the latest version of the Smart TPM utility from GIGABYTE's website. If you have installed Ultra TPM earlier, you can install
Table of Contents. TPM Configuration Procedure... 2. 1. Configuring the System BIOS... 2
Table of Contents TPM Configuration Procedure... 2 1. Configuring the System BIOS... 2 2. Installing the Infineon TPM Driver and the GIGABYTE Ultra TPM Utility... 3 3. Initializing the TPM Chip... 4 3.1.
Advanced Configuration Steps
Advanced Configuration Steps After you have downloaded a trial, you can perform the following from the Setup menu in the MaaS360 portal: Configure additional services Configure device enrollment settings
National Cyber Security Month 2015: Daily Security Awareness Tips
National Cyber Security Month 2015: Daily Security Awareness Tips October 1 New Threats Are Constantly Being Developed. Protect Your Home Computer and Personal Devices by Automatically Installing OS Updates.
MCTS Guide to Microsoft Windows 7. Chapter 7 Windows 7 Security Features
MCTS Guide to Microsoft Windows 7 Chapter 7 Windows 7 Security Features Objectives Describe Windows 7 Security Improvements Use the local security policy to secure Windows 7 Enable auditing to record security
Sophos Mobile Control Startup guide. Product version: 3
Sophos Mobile Control Startup guide Product version: 3 Document date: January 2013 Contents 1 About this guide...3 2 What are the key steps?...5 3 Log in as a super administrator...6 4 Activate Sophos
Secure Email Frequently Asked Questions
Secure Email Frequently Asked Questions Frequently Asked Questions Contents General Secure Email Questions and Answers Forced TLS Questions and Answers SecureMail Questions and Answers Glossary Support
How to configure Mac OS X Server
How to configure Mac OS X Server By Rob Buckley In the previous article in this series, we showed you how to secure a Mac using the functions built into its operating system, OS X. See photo story here
STRONGER AUTHENTICATION for CA SiteMinder
STRONGER AUTHENTICATION for CA SiteMinder Adding Stronger Authentication for CA SiteMinder Access Control 1 STRONGER AUTHENTICATION for CA SiteMinder Access Control CA SITEMINDER provides a comprehensive
imail Frequently Asked Questions (FAQs) 27 July 2015 Version 2.2
imail Frequently Asked Questions (FAQs) 27 July 2015 Version 2.2 Owner: Cynthia Tan IT Services Table of Contents GENERAL FAQS... 4 1. How to access to Sunway imail account?... 4 2. I can t login to my
Architecture and Data Flow Overview. BlackBerry Enterprise Service 10 721-08877-123 Version: 10.2. Quick Reference
Architecture and Data Flow Overview BlackBerry Enterprise Service 10 721-08877-123 Version: Quick Reference Published: 2013-11-28 SWD-20131128130321045 Contents Key components of BlackBerry Enterprise
SonicWALL Mobile Connect. Mobile Connect for OS X 3.0. User Guide
SonicWALL Mobile Connect Mobile Connect for OS X 3.0 User Guide Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your system. CAUTION: A CAUTION
Secure Email User Guide. Guidance for Recipients of Secure Email Messages from Lloyds Banking Group
Guidance for Recipients of Secure Email Messages from Lloyds Banking Group Version: 1.3 Last updated: 14/04/2016 1 Introduction This user guide is intended for third party email users users who receive,
McAfee EETech for Mac 6.2 User Guide
McAfee EETech for Mac 6.2 User Guide COPYRIGHT Copyright 2012 McAfee, Inc. Do not copy without permission. TRADEMARK ATTRIBUTIONS McAfee, the McAfee logo, McAfee Active Protection, McAfee AppPrism, McAfee
ONE Mail Direct for Mobile Devices
ONE Mail Direct for Mobile Devices User Guide Version: 2.0 Document ID: 3292 Document Owner: ONE Mail Product Team Copyright Notice Copyright 2014, ehealth Ontario All rights reserved No part of this document
Sophos Mobile Control SaaS startup guide. Product version: 6
Sophos Mobile Control SaaS startup guide Product version: 6 Document date: January 2016 Contents 1 About this guide...4 2 About Sophos Mobile Control...5 3 What are the key steps?...7 4 Change your password...8
Sophos Mobile Control Startup guide. Product version: 3.5
Sophos Mobile Control Startup guide Product version: 3.5 Document date: July 2013 Contents 1 About this guide...3 2 What are the key steps?...5 3 Log in as a super administrator...6 4 Activate Sophos Mobile
1. What are the System Requirements for using the MaaS360 for Exchange ActiveSync solution?
MaaS360 FAQs This guide is meant to help answer some of the initial frequently asked questions businesses ask as they try to figure out the who, what, when, why and how of managing their smartphone devices,
This manual will help you connect your Microsoft Windows XP, Vista, or 7, or Apple OS X computer to the University of Maryland campus data network.
This manual will help you connect your Microsoft Windows XP, Vista, or 7, or Apple OS X computer to the University of Maryland campus data network. Prerequisites for Network Registration: 1. In order to
efolder White Paper: HIPAA Compliance
efolder White Paper: HIPAA Compliance October 2014 Copyright 2014, efolder, Inc. Abstract This paper outlines how companies can use certain efolder services to facilitate HIPAA and HITECH compliance within
Management of Hardware Passwords in Think PCs.
Lenovo Corporation March 2009 security white paper Management of Hardware Passwords in Think PCs. Ideas from Lenovo Notebooks and Desktops Workstations and Servers Service and Support Accessories Introduction
Certified Secure Computer User
Certified Secure Computer User Exam Info Exam Name CSCU (112-12) Exam Credit Towards Certification Certified Secure Computer User (CSCU). Students need to pass the online EC-Council exam to receive the
Server Settings Mobile Devices
*****This document is intended to be used by faculty and staff only***** Faculty and Staff at Booth can configure their Android, BlackBerry, iphone, Palm webos or other Active Sync device to connect to
INFORMATION SECURITY GUIDE. Employee Teleworking. Information Security Unit. Information Technology Services (ITS) July 2013
INFORMATION SECURITY GUIDE Employee Teleworking Information Security Unit Information Technology Services (ITS) July 2013 CONTENTS 1. Introduction... 2 2. Teleworking Risks... 3 3. Safeguards for College
BYOD Guidance: BlackBerry Secure Work Space
GOV.UK Guidance BYOD Guidance: BlackBerry Secure Work Space Published 17 February 2015 Contents 1. About this guidance 2. Summary of key risks 3. Secure Work Space components 4. Technical assessment 5.
Quick Start. Nighthawk X8 AC5300 Tri-Band WiFi Router Model R8500. Package Contents. NETGEAR, Inc. 350 East Plumeria Drive San Jose, CA 95134 USA
Support Thank you for purchasing this NETGEAR product. You can visit www.netgear.com/support to register your product, get help, access the latest downloads and user manuals, and join our community. We
EnCase Forensic Product Overview
GUIDANCE SOFTWARE EnCase Forensic EnCase Forensic Product Overview The Standard in Digital Investigations GUIDANCE SOFTWARE EnCase Forensic EnCase Forensic Version 7 The mission of Guidance Software has
COMMONWEALTH OF PENNSYLVANIA DEPARTMENT S OF PUBLIC WELFARE, INSURANCE AND AGING
COMMONWEALTH OF PENNSYLVANIA DEPARTMENT S OF PUBLIC WELFARE, INSURANCE AND AGING INFORMATION TECHNOLOGY STANDARD Name Of Standard: Mobile Device Standard Domain: Security Date Issued: 09/07/2012 Date Revised:
