Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:
You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.
Logging in...
Previously on "Laptop Encryption, FIP 140-2 and public sector work"
Not assuming that encryption will make everything alright. However, it would be so helpful if we could get to the point where I didn't have to lug multiple laptops all over the place....
DOn't assume that by using the right encryption you can stick certain information on your laptop. It all comes down to the agency or dept you work with and their relevant policies. This is increasingly important for cleared contractors as, if you breach the rules, you may lose your clearance permanently.
That said, check out http://www.alertsec.co.uk. Approved encryption through a managed service for 8 notes a month (I believe)...
I was expecting to get a shed load of work out of this but the bigwigs are moaning already so they're introducing a waiver system, the upshot being the most important people which will be privy to the most sensitive information still wont have full encryption.
sounds about right.... after all, senior people don't do silly things like leave their laptops in the back of their car....
My current client - the laptop hard-drives are fully encrypted with something called safeboot. At boot time you are prompted with a username and password (which requires changing every month), Otherwise the laptop won't even boot. Everything written and read is encrypted. It really slows the thing down.
This covers the entire MoD as well, the current system has encryption but only on a separate partition so there's nothing to stop users just dragging and dropping data elsewhere on the hard drive.
I was expecting to get a shed load of work out of this but the bigwigs are moaning already so they're introducing a waiver system, the upshot being the most important people which will be privy to the most sensitive information still wont have full encryption.
Laptop Encryption, FIP 140-2 and public sector work
Those of you who are working on public sector projects will probably be aware of the recent ban imposed on taking unencrypted laptops out of government facilities.
I've recently been passed some revised guidance (due for release today/tomorrow) that will be sent out to departments requiring them to ensure that all contractors/consultants confirm either that:
- they do not have any government data on their personal/company laptops
OR
- that they comply with the standards set out in the Data Protection Act, and in particular that their laptop hard disc drives are encrypted to FIP 140-2 standards
I do encrypt my hard disc at present (using PGP), but am no security expert. Can any of you wiser heads advise on...
- what products they've used/would recommend to encrypt a laptop to meet FIP 140-2
- what else they would recommend a one-person contracting company to do in order to comply with the Data Protection Act (in terms of written data protection policy, backup and archive procedures etc).
The current situation is a pain in the a**e, but there is a potential payoff. If I can get a standard set of policies/procedures for compliance, then it should be possible to start operating using only the one laptop (my company's) rather than having to lug around my client's laptop as well (may also help deal with some of the IR35 pointers that chase you around when doing government work....)
Leave a comment: