BitLocker is a full-disk encryption feature provided by Microsoft Windows. SBA deploys Bit Locker across all its user laptops. BitLocker offers machine-level encryption. It provides several essential elements aimed at enhancing data protection and safeguarding sensitive information that, includes:
- Full-Disk Encryption: BitLocker encrypts the entire hard drive, including the operating system, system files, and user data. This comprehensive encryption ensures that all data stored on the device is protected, even if the device is lost, stolen, or accessed by unauthorised individuals. SBA deploys full disk encryption on user machines.
- Trusted Platform Module (TPM) Integration: BitLocker utilises TPM, a hardware component, to store encryption keys securely. TPM provides hardware-based security features, including protected storage and encryption key generation, making it harder for attackers to tamper with or bypass encryption.
- Multi-Factor Authentication (MFA): BitLocker supports various authentication methods to unlock encrypted drives, including PINs, passwords, smart cards, and USB keys.
- Pre-Boot Authentication: Before the operating system loads, BitLocker prompts users to enter authentication credentials. This pre-boot authentication prevents unauthorised access to the encrypted drive, even if the device is stolen or tampered with.
- Recovery Key Options: BitLocker provides recovery key options to regain access to encrypted drives in case of forgotten passwords or lost authentication devices.
By leveraging BitLocker's features within SBA’s IT Security policy, SBA aims to have full physical protection of laptops against thefts, loss or tampering.
USB Level Protection
USB device protection is a critical aspect of SBA's cybersecurity policy, and SBA deploys blocking all USB devices by default or allows only authorised and whitelisted devices.
Laptops are disabled for USB use, and only mouse and keyboard use is allowed.
By incorporating these USB device protection measures into SBA’s cybersecurity policy, we aim to mitigate the risks associated with USB devices.