Solved

Server Data Encryption

Posted on 2011-02-11
6
393 Views
Last Modified: 2012-05-11
Over the last several years, we have been increasing data security and making every effort to better secure our client data, particularly PII.  As a result, we are to the point where we are evaluating the need to encrypt the data on all of our branch office servers, which includes both Exchange and files shares.  
 
We are interested in finding out if any of you are encrypting your server data and if so, how are you accomplishing it?  Has anyone used EFS on file shares and Exchange and if so, what are the performance implications?  Has anyone used self encrypting drives and have you had any issues or performance implications with them?  
0
Comment
Question by:Netopsprime
  • 3
  • 2
6 Comments
 
LVL 25

Expert Comment

by:RobMobility
ID: 34872174
Hi,

If you're running Server 2008 you have the option of BitLocker encryption - this protects the drive when powered down:

http://technet.microsoft.com/en-us/library/cc731549(WS.10).aspx

Regards,


RobMobility.
0
 

Author Comment

by:Netopsprime
ID: 34872270
I am using Windows Server 2003 with Exchange 2003.
0
 

Expert Comment

by:mary_87
ID: 34872314
The Best Idea is to establish VPN Connection between the physical locations for security
so if you can send me the network diagram for the whole offices so I can give you the best design to your network .
also is there any routers, firewalls are used or you just use windows servers?
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:Netopsprime
ID: 34872353
I'm not interested in data in transit, I have that covered.  I am interested in data at rest or mitigating against something like a server being stolen, etc.
0
 
LVL 25

Accepted Solution

by:
RobMobility earned 500 total points
ID: 34872519
Hi,

Perhaps you should consider a 3rd party data at rest solution that's compatible with any RAID configuration you have. Ideally, 3 factor authentication should be used - e.g. TPM, USB and PIN or USB key, PIN and password.

That way if the server is stolen, nobody can start it or access data on the drives as they are in an encrypted state.

Go for a commerical tool with FIPS validated encryption.

Regards.


RobMobility.
0
 

Author Closing Comment

by:Netopsprime
ID: 34982566
We believe of all the options available Self Encrypting Drives will be the best solution. Thx all.
0

Featured Post

Are end users causing IT problems again?

You’ve taken the time to design and update all your end user’s email signatures, only to find out they’re messing up the HTML, changing the font and ruining the imagery. What can you do to prevent this? Find out how you can save your signatures from end users today.

Join & Write a Comment

Not sure what the best email signature size is? Are you worried about email signature image size? Follow this best practice guide.
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now