?
Solved

Server Data Encryption

Posted on 2011-02-11
6
Medium Priority
?
425 Views
Last Modified: 2012-05-11
Over the last several years, we have been increasing data security and making every effort to better secure our client data, particularly PII.  As a result, we are to the point where we are evaluating the need to encrypt the data on all of our branch office servers, which includes both Exchange and files shares.  
 
We are interested in finding out if any of you are encrypting your server data and if so, how are you accomplishing it?  Has anyone used EFS on file shares and Exchange and if so, what are the performance implications?  Has anyone used self encrypting drives and have you had any issues or performance implications with them?  
0
Comment
Question by:Netopsprime
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 25

Expert Comment

by:RobMobility
ID: 34872174
Hi,

If you're running Server 2008 you have the option of BitLocker encryption - this protects the drive when powered down:

http://technet.microsoft.com/en-us/library/cc731549(WS.10).aspx

Regards,


RobMobility.
0
 

Author Comment

by:Netopsprime
ID: 34872270
I am using Windows Server 2003 with Exchange 2003.
0
 

Expert Comment

by:mary_87
ID: 34872314
The Best Idea is to establish VPN Connection between the physical locations for security
so if you can send me the network diagram for the whole offices so I can give you the best design to your network .
also is there any routers, firewalls are used or you just use windows servers?
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 

Author Comment

by:Netopsprime
ID: 34872353
I'm not interested in data in transit, I have that covered.  I am interested in data at rest or mitigating against something like a server being stolen, etc.
0
 
LVL 25

Accepted Solution

by:
RobMobility earned 1500 total points
ID: 34872519
Hi,

Perhaps you should consider a 3rd party data at rest solution that's compatible with any RAID configuration you have. Ideally, 3 factor authentication should be used - e.g. TPM, USB and PIN or USB key, PIN and password.

That way if the server is stolen, nobody can start it or access data on the drives as they are in an encrypted state.

Go for a commerical tool with FIPS validated encryption.

Regards.


RobMobility.
0
 

Author Closing Comment

by:Netopsprime
ID: 34982566
We believe of all the options available Self Encrypting Drives will be the best solution. Thx all.
0

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question