0% found this document useful (0 votes)
118 views6 pages

Data Encryption Policy Overview

This document outlines ReCom Consulting Ltd.'s data encryption policy. It requires encryption of confidential information and personally identifiable information both at rest and in transit. The policy provides guidance on appropriate encryption technologies and ensures regulations are followed. It applies to all staff involved with applications and systems containing sensitive data. The policy mandates encryption of data on devices, networks, emails and other transmissions to protect information and comply with security standards.

Uploaded by

Kamrul Hasan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
118 views6 pages

Data Encryption Policy Overview

This document outlines ReCom Consulting Ltd.'s data encryption policy. It requires encryption of confidential information and personally identifiable information both at rest and in transit. The policy provides guidance on appropriate encryption technologies and ensures regulations are followed. It applies to all staff involved with applications and systems containing sensitive data. The policy mandates encryption of data on devices, networks, emails and other transmissions to protect information and comply with security standards.

Uploaded by

Kamrul Hasan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Title Page
  • Scope
  • Purpose
  • Overview
  • At-Rest Encryption
  • Encryption Key Length
  • Portable Device Encryption
  • Access
  • In-Transit Encryption
  • Encryption Key Management
  • Policy Version History
  • Audit Controls and Management
  • Enforcement

Data Encryption Policy 1

Data Encryption Policy

ReCom Consulting Ltd.


Data Encryption Policy 2

1. Overview
ReCom Consulting Ltd. “Confidential Information” and Employee, Educator or Student Personally
Identifiable Information (“PII”) must be protected while stored at-rest and in-transit. Appropriate
encryption technologies must be used to protect the ReCom Consulting Ltd. .

2. Purpose
The purpose of this policy is to provide guidance on the use of encryption technologies to protect ReCom
Consulting Ltd. data, information resources, and other Confidential Information or PII while stored at rest
or transmitted between parties. This policy also provides direction to ensure that regulations are followed.

3. Scope
This policy applies to all ReCom Consulting Ltd. staff that create, deploy, transmit, or support application
and system software containing Confidential Information or PII. It addresses encryption policy and
controls for Confidential Information or PII that is at rest (including portable devices and removable
media), data in motion (transmission security), and encryption key standards and management.

4. Policy
A. ACCESS

The [Insert Appropriate Role] or their designee shall ensure:

o Policies, procedures, scenarios, and processes must identify Confidential


Information or PII that must be encrypted to protect against persons or programs
that have not been granted access.

o ReCom Consulting Ltd. implements appropriate mechanisms to encrypt and


decrypt Confidential Information or PII whenever deemed appropriate. Internal
procedures shall specify how ReCom Consulting Ltd. transmits sensitive
information as well as how often the information is transmitted.

o When encryption is needed based on data classification to protect Confidential


Information or PII during transmission. Procedures shall specify the methods of
encryption used to protect the transmission of Confidential Information or PII.

o Logical user access is managed separately and independently of native


operating system authentication and access control mechanisms (for example,
by not using local user account databases or general network login credentials)
when disk encryption is used rather than file or column level database
encryption.

B. ENCRYPTION KEY LENGTH

ReCom Consulting Ltd. uses software encryption technology to protect Confidential


Information or PII. To provide the highest-level security while balancing throughput and
response times, encryption key lengths should use current industry standard encryption
algorithms for Confidential Information or PII.

ReCom Consulting Ltd.


Data Encryption Policy 3

The use of proprietary encryption algorithms are not allowed unless reviewed by qualified
experts outside of the vendor in question and approved by ReCom Consulting Ltd.
management.

C. AT-REST ENCRYPTION

• Hard drives that are not fully encrypted (e.g., disks that one or more un-encrypted
partitions, virtual disks) but connect to encrypted USB devices, may be vulnerable to
security breach from the encrypted region to the unencrypted region. Full disk
encryption avoids this problem and shall be the method of choice for user devices
containing Confidential Information or PII.

• Confidential Information or PII at rest on computer systems owned by and located


within ReCom Consulting Ltd. controlled spaces, devices, and networks should be
protected by one or more of the following mechanisms:

o Disk/File System Encryption (e.g. Microsoft EFS technology)

o Use of Virtual Private Networks (VPN’s) and Firewalls with strict access
controls that authenticate the identity of those individuals accessing the
Confidential Information or PII

o Sanitizing, redacting, and/or de-identifying the data requiring protection


during storage to prevent unauthorized risk and exposure (e.g., masking or
blurring PII)

o Supplemental compensating or complimentary security controls including


complex passwords, and physical isolation/access to the data

o Strong cryptography on authentication credentials (i.e. passwords/phrases)


shall be made unreadable during transmission and storage on all information
systems

o Password protection to be used in combination with all controls including


encryption

o File systems, disks, and tape drives in servers and Storage Area Network
(SAN) environments are encrypted using industry standard encryption
technology

o Computer hard drives and other storage media that have been encrypted
shall be sanitized to prevent unauthorized exposure upon return for
redistribution or disposal

D. PORTABLE DEVICE ENCRYPTION

• Portable devices (e.g. smart-phones, flash cards, SD cards, USB file storage)
represent a specific category of devices that contain data-at-rest. Many incidents
involving unauthorized exposure of Confidential Information or PII are the result of
stolen or lost portable computing devices. The most reliable way to prevent
exposure is to avoid storing Confidential Information or PII on these devices.

• As a general practice, Confidential Information or PII shall not be copied to or stored


on a portable computing device or ReCom Consulting Ltd. -owned computing device.
However, in situations requiring Confidential Information or PII to be stored on such

ReCom Consulting Ltd.


Data Encryption Policy 4

devices, encryption reduces the risk of unauthorized disclosure in the event that the
device becomes lost or stolen. The following procedures shall be implemented when
using portable storage:

o Hard drives (laptops, tablets, smartphones and personal digital assistants


(PDAs)) shall be encrypted using products and/or methods approved by
ReCom Consulting Ltd. Project Manager. Unless otherwise approved by
management, such devices shall have full disk encryption with pre-boot
authentication.

o Devices shall not be used for the long-term storage of any Confidential
Information or PII.

o All devices shall have proper and appropriate protection mechanisms


installed including approved anti-malware/virus software, personal firewalls
with unneeded services and ports turned off, and properly configured
applications.

o Removable media including CD’s, DVD’s, USB flash drives, etc. shall not be
used to store Confidential Information or PII.

E. IN-TRANSIT ENCRYPTION

In-transit encryption refers to transmission of data between end-points. The intent of these
policies is to ensure that Confidential Information or PII transmitted between companies,
across physical networks, or wirelessly is secured and encrypted in a fashion that protects
student Confidential Information or PII from a breach.

The IT Security Team or their designee shall ensure:

• Formal transfer policies, protocols, procedures, and controls are implemented to


protect the transfer of information through the use of all types of communication and
transmission facilities.

• Users follow ReCom Consulting Ltd. acceptable use policies when transmitting data
and take particular care when transmitting or re-transmitting Confidential Information
or PII received from non-ReCom Consulting Ltd. staff.

• Strong cryptography and security protocols (e.g. TLS, IPSEC, SSH, etc.) are used to
safeguard Confidential Information or PII during transmission over open public
networks. Such controls include:

o Only accepting trusted keys and certificates, protocols in use only support
secure versions or configurations, and encryption strength is appropriate for
the encryption methodology in use.

o Public networks include but are not limited to the Internet, Wireless
technologies, including 802.11, Bluetooth, and cellular technologies.

o Confidential Information or PII transmitted in e-mail messages are encrypted.


Any Confidential Information or PII transmitted through a public network (e.g.,
Internet) to and from vendors, customers, or entities doing business with
ReCom Consulting Ltd. must be encrypted or transmitted through an
encrypted tunnel (VPN) or point-to-point tunneling protocols (PPTP) that
include current transport layer security (TLS) implementations.

ReCom Consulting Ltd.


Data Encryption Policy 5

o Wireless (Wi-Fi) transmissions used to access ReCom Consulting Ltd.


computing devices or internal networks must be encrypted using current
wireless security standard protocols (e.g. RADIUS, WPS private/public keys
or other industry standard mechanisms).

o Encryption or an encrypted/secured channel is required when users access


ReCom Consulting Ltd. Confidential Information or PII remotely from a
shared network, including connections from a Bluetooth device to a ReCom
Consulting Ltd. PDA or cell phone.

o Secure encrypted transfer of documents and Confidential Information or PII


over the internet uses current secure file transfer programs such as “SFTP”
(FTP over SSH) and secure copy command (SCP).

o All non-console administrative access such as browser/web based


management tools are encrypted using SSL based browser technologies
using the most current security algorithm.

F. ENCRYPTION KEY MANAGEMENT

Effective enterprise public and private key management is a crucial element in ensuring
encryption system security. Key management procedures must ensure that authorized
users can access and decrypt all encrypted Confidential Information or PII using controls
that meet operational needs. ReCom Consulting Ltd. key management systems are
characterized by following security precautions and attributes:

• ReCom Consulting Ltd. uses procedural controls to enforce the concepts of least
privilege and separation of duties for staff. These controls apply to persons involved
in encryption key management or who have access to security-relevant encryption
key facilities and processes, including Certificate Authority (CA) and Registration
Authority (RA), and/or contractor staff.

• IT Security Manager shall verify backup storage for key passwords, files, and
Confidential Information or PII to avoid single point of failure and ensure access to
encrypted Confidential Information or PII.

• Key management should be fully automated. ReCom Consulting Ltd Project Manager
should not have the opportunity to expose a key or influence the key creation.

• Keys in storage and transit must be encrypted.

• Private keys must be kept confidential.

• Application and system resource owners should be responsible for establishing data
encryption policies that grant exceptions based on demonstration of a business need
and an assessment of the risk of unauthorized access to or loss of Confidential
Information or PII.

The [Insert Appropriate Role] or their designee shall ensure:

• Decryption keys are not associated with user accounts.

• Documentation and procedures exist to protect keys used to secure stored


Confidential Information or PII against disclosure and misuse.

ReCom Consulting Ltd.


Data Encryption Policy 6

• Restrict access to cryptographic keys to the fewest number of custodians


necessary.

• Cryptographic keys are stored in the fewest possible locations.

• Key management processes and procedures for cryptographic keys are fully
documented.

• Retirement or replacement (for example, archiving, destruction, and/or revocation)


of keys as deemed necessary when the integrity of the key has been weakened or
keys are suspected of being compromised.

Note: If retired or replaced cryptographic keys need to be retained, these keys must be
securely archived. Archived cryptographic keys should only be used for
decryption/verification purposes.

Cryptographic key custodians shall formally acknowledge that they understand and
accept their key-custodian responsibilities.

5. Audit Controls and Management


On-demand documented procedures and evidence of practice should be in place for this operational
policy as part of ReCom Consulting Ltd. operational methodology.

• ReCom Consulting Ltd. shall inventory encrypted devices and validate implementation of
encryption products at least annually.

• Documentation shall exist for key management procedures.

• At-Rest encryption procedures exist and can be demonstrated.

• In-Transit encryption procedures exist and can be demonstrated.

• Exception logs exist and can be produced for those resources that are excluded from this
policy.

6. Enforcement
Staff members found in policy violation may be subject to disciplinary action, up to and including
termination.

7. Distribution
This policy is to be distributed to all ReCom Consulting Ltd. staff and contractors using ReCom
Consulting Ltd. Confidential Information or PII resources.

8. Policy Version History

Version Date Description Approved By

1.0 9/13/2019 Initial Policy Drafted Khandoker Atiqur Rahman

ReCom Consulting Ltd.

Common questions

Powered by AI

Data at rest on ReCom Consulting Ltd. systems and devices is protected through full disk encryption, especially where the devices store Confidential Information or PII. They utilize approved encryption technologies like Microsoft EFS, utilize VPNs and firewalls, and employ sanitizing and redacting processes to mask sensitive data. Additionally, strong cryptography is applied to authentication credentials, and sanitized hard drives and media are managed accordingly for redistribution or disposal .

ReCom Consulting Ltd. restricts the use of removable media for storing Confidential Information or PII due to the increased risk of unauthorized exposure and potential data breaches. They advise against storing such information on removable media such as CDs, DVDs, and USB flash drives. If it's absolutely necessary to transfer this data using such media, encryption is essential to protect the information during storage and transport, reducing the risk of data leaks should the media be lost or stolen .

ReCom Consulting Ltd. employs strong cryptography and security protocols like TLS, IPSEC, and SSH to protect Confidential Information or PII during transmission over public networks. This includes mechanisms such as only accepting trusted keys and certificates, using secure versions or configurations of protocols, and ensuring encryption strength is consistent with the encryption methodology in use. Furthermore, all emails containing Confidential Information must be encrypted, and data transmitted through public networks must either be encrypted or sent through an encrypted tunnel or protocol such as VPN or PPTP utilizing current TLS implementations. Additionally, wireless transmissions are secured using industry-standard protocols like RADIUS and WPA2 .

ReCom Consulting Ltd. requires encryption keys to be managed using procedural controls that enforce least privilege and separation of duties for staff involved in key management. They have automation in place to minimize human interaction with key creation to prevent exposure. Encryption keys in storage and transit must be encrypted, and private keys must remain confidential. Documentation exists to protect these keys from unauthorized disclosure, and access is restricted to the minimum number of custodians. They also enforce procedures for key retirement, replacement, and secure archiving of keys when necessary .

Portable device encryption plays a critical role in preventing unauthorized exposure of data at ReCom Consulting Ltd. by ensuring that any Confidential Information or PII stored on devices like laptops and smartphones is fully encrypted. This reduces risk in cases of device loss or theft. ReCom Consulting Ltd. mandates full disk encryption with pre-boot authentication for portable devices and advises against long-term storage of sensitive data on these devices. Additional protection mechanisms like anti-malware software and personal firewalls further protect these devices from unauthorized access .

ReCom Consulting Ltd. recommends several compensating security controls for protecting data at rest. These include complex passwords, physical isolation and access restrictions, the use of strong cryptography for authentication credentials, and mandatory password protection with all other security controls. These additional measures complement encryption and help ensure that even if one layer of security is breached, other layers provide continued protection against unauthorized access .

ReCom Consulting Ltd.'s policies on data transmission are highly effective in safeguarding data. They employ strong encryption protocols like TLS, IPSEC, and SSH for transmission over public networks and require encryption for all wireless transmissions using secure protocols such as WPA2. These protocols ensure that data, including emails and transmissions through public networks, remains secure from unauthorized access. The policies also include stringent cryptography standards and verify that all necessary protocols support these encryption strengths and are trusted. By covering an extensive range of transmission scenarios and applying rigid security measures, ReCom Consulting Ltd. effectively mitigates risks related to data transmission .

Full disk encryption is preferred for user devices within ReCom Consulting Ltd. because it prevents unauthorized access by encrypting the entire storage device, thereby eliminating vulnerabilities that could exist between encrypted and unencrypted regions of the drive. This approach is particularly crucial on user devices to prevent breaches arising from the exposure of Confidential Information or PII in case devices are lost or stolen .

ReCom Consulting Ltd. implements documented procedures to ensure the security of encryption keys, which include restricting access to the fewest possible number of custodians, ensuring keys are stored in as few locations as possible, and documenting key management processes. These measures are crucial for preventing unauthorized access and potential data breaches. By maintaining these controls, the organization ensures that only personnel with essential responsibilities have access, thus minimizing risks associated with key exposure. Additionally, procedures permit the retirement or replacement of keys deemed compromised .

ReCom Consulting Ltd. ensures proper management of archived cryptographic keys through secure archiving methods, only allowing these keys to be used solely for decryption or verification purposes. They require key custodians to formally acknowledge their responsibilities related to key management. Additionally, the company has procedures for the retirement and replacement of keys when their integrity is weakened or compromised, ensuring such keys are securely managed or destroyed if not required .

Data Encryption Policy 
1 
 
 
 
ReCom Consulting Ltd. 
 
 
 
 
 
Data Encryption Policy
Data Encryption Policy 
2 
 
 
 
ReCom Consulting Ltd. 
 
1. Overview 
ReCom Consulting Ltd.  “Confidential Information” and
Data Encryption Policy 
3 
 
 
 
ReCom Consulting Ltd. 
The use of proprietary encryption algorithms are not allowed unless r
Data Encryption Policy 
4 
 
 
 
ReCom Consulting Ltd. 
devices, encryption reduces the risk of unauthorized disclosure in th
Data Encryption Policy 
5 
 
 
 
ReCom Consulting Ltd. 
o 
Wireless (Wi-Fi) transmissions used to access ReCom Consulting Ltd
Data Encryption Policy 
6 
 
 
 
ReCom Consulting Ltd. 
• 
Restrict access to cryptographic keys to the fewest number of cust

You might also like