Encrypting data at rest: how will it help our marines and sailors?

CHIPS, Oct-Dec, 2007 by Darin Dropinski, James Mauck

Encryption Guidance

OMB policy does not mandate encryption of unclassified data on servers or backups. However, encrypting media on servers and backups is a good idea, and the DON may mandate it in the future. At this time, the Department is focusing on the devices that are most vulnerable to theft or loss--those that are portable.

Until the DAR encryption solution is deployed, WinZip 9.0 should be used to encrypt sensitive information. WinZip is a standard application on all NMCI computers; instructions on how to use WinZip are located on the NMCI homepage at http://homeport/.> It is everyone's responsibility to ensure proper handling of sensitive information. The deployment of a data at rest encryption solution does not replace the need to be good stewards of the information with which we are entrusted. Think about the information you want to take outside the DON network--if you do not really need it--then leave it.

If you need the information on travel or at home, follow appropriate DoD and DON policies for obtaining the required authorization to transport/store the data and ensure it is encrypted.

It is important to note that only government-owned thumb drives, laptop PCs and portable media can be used to transport or store PII or other sensitive information. Mr. Darin Dropinski is the deputy team leader for information assurance and network security. Mr. James Mauck is the subject matter expert for information assurance and network security.

References

The following policies can be found on the DON CIO Web site at www.doncio.navy.mil.

OMB Policy Memo 06-16, June 23, 2007, Protection of Sensitive Unclassified Agency Information.

DoD Memo July 3, 2007, Encryption of Sensitive Unclassified Data at Rest (DAR) on Mobile Computing Devices and Removable Storage Media Used Within the DoD.

DON CIO message dated 171952ZAPR2007, Safeguarding Personally Identifiable Information (PII).

Mr. Darin Dropinski is the deputy team leader for information assurance and network security.

Mr. James Mauck is the subject matter expert for information assurance and network security.

COPYRIGHT 2007 U.S. Navy
COPYRIGHT 2008 Gale, Cengage Learning

 

BNET TalkbackShare your ideas and expertise on this topic

Please add your comment:

  1. You are currently: a Guest |
  2.  

Basic HTML tags that work in comments are: bold (<b></b>), italic (<i></i>), underline (<u></u>), and hyperlink (<a href></a)

advertisement
CXO UnpluggedSmart Business interviews on BNET

See and hear how senior level executives across the Asia Pacific are developing smart business ideas across a variety of sectors. The focus is on the future, and on how businesses need to evolve.

advertisement
  • Click Here
  • Click Here
  • Click Here
advertisement

Content provided in partnership with Thompson Gale