<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bitlocker on USB drives for GDPR in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/Bitlocker-on-USB-drives-for-GDPR/m-p/10562#M480</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bitlocker is backed by multiple FIPS (CMVP and CAVP) validations. Windows 10 was Common Criteria&amp;nbsp;validated as well, using the CAVP validations to back up its AES, XTS, RSA, and SHS implementations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not a fancy, big-city GDPR expert, but having been a CC/FIPS evaluator, it seems to me that if&amp;nbsp;the cryptographic implementations are good enough for use by the US and allied national governments then&amp;nbsp;they are probably good enough for GDPR.&lt;/P&gt;</description>
    <pubDate>Tue, 22 May 2018 14:33:58 GMT</pubDate>
    <dc:creator>Badfilemagic</dc:creator>
    <dc:date>2018-05-22T14:33:58Z</dc:date>
    <item>
      <title>Bitlocker on USB drives for GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Bitlocker-on-USB-drives-for-GDPR/m-p/10556#M479</link>
      <description>&lt;P&gt;Did anybody look into Microsoft BitLocker on a USB drive and if the encryption level of BitLocker would be sufficiently secure for GDPR?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our stores we deal with Personal data and ship&amp;nbsp;this between the stores and the office, an encrypted USB drive would be ideal for this purpose.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Arthur Vermeer.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:46:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Bitlocker-on-USB-drives-for-GDPR/m-p/10556#M479</guid>
      <dc:creator>AVermeer</dc:creator>
      <dc:date>2023-10-09T08:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker on USB drives for GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Bitlocker-on-USB-drives-for-GDPR/m-p/10562#M480</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bitlocker is backed by multiple FIPS (CMVP and CAVP) validations. Windows 10 was Common Criteria&amp;nbsp;validated as well, using the CAVP validations to back up its AES, XTS, RSA, and SHS implementations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not a fancy, big-city GDPR expert, but having been a CC/FIPS evaluator, it seems to me that if&amp;nbsp;the cryptographic implementations are good enough for use by the US and allied national governments then&amp;nbsp;they are probably good enough for GDPR.&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 14:33:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Bitlocker-on-USB-drives-for-GDPR/m-p/10562#M480</guid>
      <dc:creator>Badfilemagic</dc:creator>
      <dc:date>2018-05-22T14:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker on USB drives for GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Bitlocker-on-USB-drives-for-GDPR/m-p/10583#M481</link>
      <description>&lt;P&gt;Dear Arthur,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;since there is no whitelist of products, there are two things that could very likely be cheked during a customer or government audit or if you need to present your crypto management during contract negotiation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Algorithms&lt;/LI&gt;&lt;LI&gt;Key Management (ideally managed by policy)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;In terms of algorithms, there's nothing wrong with Bitlocker.&lt;/P&gt;&lt;P&gt;Key Management is completely up to you but might screw up the best encryption if not carried out properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 17:07:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Bitlocker-on-USB-drives-for-GDPR/m-p/10583#M481</guid>
      <dc:creator>oms</dc:creator>
      <dc:date>2018-05-22T17:07:45Z</dc:date>
    </item>
  </channel>
</rss>

