Configuring the Data Protection Policy
Use Data Protection policies to secure sensitive data on endpoints by configuring Full Disk Encryption and Media Encryption & Port Protection settings.
Configuring Full Disk Encryption
Full Disk Encryption gives you the highest level of data security for Endpoint Security client computers.
It combines boot protection and strong disk encryption to ensure that only authorized users can access data stored in desktop and laptop PCs.
When you add or remove Full Disk Encryption for the Endpoint Security client, the client must restart to enforce them on the endpoint.
Check Point's Full Disk Encryption has two main components:
- Check Point Disk Encryption for Windows - Ensures that all volumes of the hard drive and hidden volumes are automatically fully encrypted. This includes system files, temporary files, and even deleted files. There is no user downtime because encryption occurs in the background without noticeable performance loss. The encrypted disk is inaccessible to all unauthorized people.
- Authentication before the Operating System Loads (Pre-boot) - Requires users to authenticate to their computers before the computer boots. This prevents unauthorized access to the operating system using authentication bypass tools at the operating system level or alternative boot media to bypass boot protection.
Full Disk Encryption also supports BitLocker Encryption for Windows Clients and FileVault Encryption for macOS
The Full Disk Encryption policy contains a pre-defined Default Policy rule, which applies to the entire organization.
Each new rule you create, has pre-defined settings, which you can then edit in the right section of the screen.
The Policy rule consists of these parts
The Policy Rule Base consists of these parts:
| Column | Description |
|---|---|
|
Rule Number |
The sequence of the rules is important because the first rule that matches traffic according to the protected scope is applied. |
|
Rule Name |
Give the rule a descriptive name. |
|
Applied to |
The protected scope to which the rule applies. |
| Full Disk Encryption |
The configurations that apply to data encryption. |
Policy toolbar options
The Policy toolbar includes these options:
| To do this | Click this |
|---|---|
| Create a new rule |
|
| Save, view, or discard changes |
|
| Duplicate a rule |
|
| Install Policy |
|
| Search for entity |
|
| Delete a rule |
|
Disable Full Disk Encryption
- Go to the Policy view.
- Click Data Protection > General.
- In the Capabilities and Exclusions pane, click Full Disk Encryption.
- In Enable Pre-boot, select OFF.
-
Smart
-
Legacy
-
Off
-
- Click Save & Install.
Disk Encryption for Windows
Ensures that all volumes of the hard drive and hidden volumes are automatically fully encrypted. This includes system files, temporary files, and even deleted files. There is no user downtime because encryption occurs in the background without noticeable performance loss. The encrypted disk is inaccessible to all unauthorized people.
Configuration Options
-
Algorithms used
Go to Advanced Settings > Encryption > Choose Algorithm
Full Disk Encryption can use these encryption algorithms
-
AES-CBC 256 bit (Default)
-
XTS-AES 128 bit
-
XTS-AES 256 bit
-
-
Volumes encrypted
By default, all drives that are detected after the installation and all visible disk volumes are encrypted. Intel Rapid Recover Technology (IRRT) are not encrypted.
Go to Advanced Settings > Encryption > Allow Self-Encrypting Drives (SED) hardware functionality - Lets Full Disk Encryption probe and use SED disks that comply with the OPAL standard. If a compatible system and disk are detected, Full Disk Encryption uses the hardware encryption on the disk instead of the traditional software encryption.
When using SED drives, leave Encrypt hidden disk volumes checked (which is the default setting)
-
AES encryption is always used with SSED drives
-
Manage SED drives in the same way as software-encrypted drives
-
-
Initial Encryption
- Encrypt entire drive - Recommended for computers that are in production and already have user data, such as documents and emails.
- Encrypt used disk space only - Encrypts only the data. Recommended for fresh Windows installations.