Compliance Guide:
Good practice in Information Handling: EncryptionBefore closing in March 2011, the UK public body; BECTA developed a number of good practice guides to help staff and contractors within schools, colleges and universities tasked with implementing data security and the protection of personal and sensitive data. These guides are based on the legal requirements set by UK law and on recommendations provided by the Information Commissioner's Office (ICO). Although Becta no longer exists, the guidance issued regarding encryption still stands as a balanced and realistic basis for any school or college needing to deploy and manage encryption within a sound security policy.
The ICO recommends that portable and mobile devices, including portable media and any other device or medium that is removed from or accessed outside of the physical secure space should be encrypted to guard against compromise. Also recommended is the secure deletion of any data no longer required and the encryption of data being transmitted electronically between systems and locations such as when using email.
Part of this process is to assign an impact level to a particular type of data being handled. Impact levels range from impact level (IL) 0 - Not Protectively Marked, through IL 1 - Protect, IL 2 - Restricted, IL 3 - Confidential, IL 4 - Secret and IL 5 - Top Secret. In practice the personal data that educational establishments handle will be impact level 2 or lower. IL2 covers data that if compromised could "cause short term distress to individual, breach statutory restrictions on the disclosure of information, for example, credit card details or medical information".
| Becta Recommendation | DESlock+ |
| Portable devices (Laptops) should be encrypted. | Full disk and file and folder encryption included. |
| Portable storage media (USB memory sticks, portable hard drives CD's and DVD's) should be encrypted. | Removable media and virtual disk encryption included. |
| Any device storing data and used outside of the secure space should be encrypted. | DESlock+ Reader and DESlock+ Go (included) allows secure access to encrypted data on a home PC. |
| Any data no longer required should be securely deleted. | DESlock+ Shredder (included) securely deletes documents and the recycle bin contents. |
| Data transmitted between systems and locations should be encrypted. | Includes Microsoft Outlook plug-in for fully integrated encrypted email and attachments. |
| Encrypt IL2 - Protect data using a CESG CCTM certified or FIPS-140-2 validated product. | CCTM certified and FIPS-140-2 validated. |

Downloads


