
Installation Guide 85
10
About Personal Edition Policies and Templates
A word about types of encryption: SDE is designed to encrypt the operating system and program files. In order to
accomplish this purpose, SDE must be able to open its key while the operating system is booting without intervention of a
password by the user. Its intent is to prevent alteration or offline attacks on the operating system by an attacker. SDE is not
intended for user data. Common and User key encryption are intended for sensitive user data because they require a user
password in order to unlock encryption keys.
Tooltips display when you hover your mouse over a policy in the Personal Edition Local Management Console.
Policies
Policy
Aggress
Protect
for All
Fixed
Drives
and Ext
Drives
PCI
Reg
Data
Breach
Reg
HIPAA
Reg
Basic
Protect
for All
Fixed
Drives
and Ext
Drives
(Def)
Basic
Protect
for All
Fixed
Drives
Basic
Protect
for Sys
Drive
Only
Basic
Protect
for Ext
Drives
Enc Dis Description
Fixed Storage Policies
SDE
Encryption
Enabled
Tru e False
This policy is the “master policy” for all other System Data
Encryption (SDE) policies. If this policy is False, no SDE
encryption takes place, regardless of other policy values.
A True value means that all data not encrypted by other
Intelligent Encryption policies will be encrypted per the SDE
Encryption Rules policy.
Changing the value of this policy requires a reboot.
SDE
Encryption
Algorithm
AES256 AES 256, AES 128, 3DES
SDE
Encryption
Rules
Encryption rules to be used to encrypt/not encrypt certain
drives, directories, and folders.
SDE Encryption Rules may be changed. However, these defaults
have been tested extensively. Removing these exclusions may
result in Windows issues, particularly after applying patch
updates.
Contact Customer Support for guidance if you are unsure about
changing the default values.
Komentarze do niniejszej Instrukcji