Lessons learned during Sandia’s encryption implementation NLIT 2009 May 2008 Sam Jones Matt Snitchler Desktop Technology Development Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL85000.
Objective Protect sensitive data on all mobile devices Meet NAP 14-2-C Cyber Security Requirement
Windows Solution Credant Mobile Guardian FIPS Certified Enterprise key management Reporting capability Supports removable media Not a silver bullet
Mac Solution FileVault Credant Mac Client (Beta) –Managed by console –Does not support Windows Credant EMS WinMagic Removable media support not integrated
Linux Solutions GnuPG RHEL 5.3 –Linux Unified Key Setup (LUKS) Does not support Windows Credant EMS Dual Boot problems Removable media support not integrated Hardware based FDE software support immature
Encryption hurts Long encryption times I/O intensive applications affected Flash drives cumbersome Large USB drives experience initial long encryption time System recovery more complex
Hardware FDE Works well with I/O intensive applications No initial encryption hit Does not work with all hardware vendors –Dell, HP, Lenovo Enterprise management solutions immature –Key management –Reporting –Wave, Secude, WinMagic Technically not FIPS Hardware FDE option on Preferred System List
Hardware encrypted flash IronKey –Multi platform Windows, Linux, Mac (Beta) –FIPS 140 certified –Expensive –Enterprise management solutions immature Key management Reporting Does not work well with Credant EMS
Questions ?