Castleforce IT Security Team
Check Point Software Technologies Ltd

Media Encryption

Check Point Media Encryption secures sensitive corporate data and blocks incoming malware by encrypting removable media such as USB storage devices, CDs and DVDs and controlling activity (read, write and execute) on ports and devices. All device content is automatically encrypted in the background for a transparent end-user experience. Unique to Check Point, users can access encrypted media securely on unmanaged computers with no client installation. As the only device and port control solution integrated with a single endpoint security agent, Check Point Media Encryption simplifies compliance and reduces administrative overhead. Now supports Windows 7.

USB drives friend or foe? Datasheet

Enquire about this product

5 Virusn5 SpywarenX SpamnX Web/IMn5 IPS/Patch Mgmtn5 Data/System Mgmtn

Check Point Media Encryption secures sensitive corporate data

Check Point Media Encryption Key Benefits

  • Comprehensive control of endpoint ports and protection of corporate data stored on removable media and devices
  • Transparent end-user experience with automatic data encryption and seamless integration with Windows CD/DVD wizard and Nero 9
  • Simplified administration and operation with single agent installation, centralized management, and central policy enforcement
  • Integrated endpoint and network security capabilities including centralized logging of data movement and media usage for streamlined compliance and forensic analysis
Preventing Data Leaks on USB Ports Datasheet

Encryption Policy Manager

Encrypts information stored on devices and removable media — Encryption Policy Manager allows users to encrypt devices and removable media using strong algorithms including 256-bit AES. Uniquely, Encryption Policy Manager can be configured to allow secure access to encrypted media when using unmanaged computers, such home or business center PCs. Alternatively, users may install a plug-in to enable device access from unmanaged PCs.

Device Manager

Protects corporate information and endpoint PCs by controlling which devices can be accessed and which ports can be used — Device Manager controls access to removable devices, such as USB flash drives, CD/DVD drives, Smartphones, and PDAs. Access can be managed using a whitelist or blacklist, or defined at a granular level by type, brand, size, or ID. Assign unique serial numbers to devices for more granular management options. Device Manager can also enable/ disable individual PC ports, such as USB, FireWire, Bluetooth, WiFi and LPT.

Check Point Media Encryption Device Manager

Removable Media Manager

Ensures that changes made to information stored on devices are authorized by the user — Removable Media Manager places a unique digital signature on each encrypted device, and whenever device contents are altered, the digital signature is updated. If the contents have been altered using a computer which does not have Media Encryption installed, the user must re-authorize the device before it can be used in the protected environment. Using DataScan (see below) and antivirus software, Removable Media Manager can also force devices to be scanned for malware before granting access.

DataScan

Prevents undesirable files, such as executables and malware, from entering endpoints through ports — DataScan can block or allow transfer of specific file types, as determined by extension and internal file structure, and block access to devices until dangerous or prohibited files have been deleted.

Program Security Guard

Safeguards information and endpoints by preventing users from creating, modifying or deleting specific file types — administrators can define protected files by extension and create exceptions for modification of files by trusted applications.

Check Point Media Encryption Program Security Guard 

Auditing and Alerts

Simplifies compliance audits and event notification — unlike other solutions, Media Encryption stores logs to a central database, enabling easy creation of detailed reports using structured queries. Administrators can also centrally monitor and audit file operations on removable devices, such as which files were moved to or from individual devices, and when. Email alerts can be configured to notify administrators about specific events.

Check Point Media Encryption Auditing and Alerts 


Contact CastleForce Check Point Partner

Check Point Media Encryption datasheet Datasheet

Compliance Standards

Castleforce can help you reach PCI DSS 

Requirement 3: Protect stored cardholder data

Protecting Stored Cardholder Data Datasheet

Castleforce can help you reach GCSx CoCo

GCSX No 6 Access Control

GCSX No 10 Mobile / Home Working

GCSX No 15 Removable Media 

Castleforce can help you reach ISO27001

A.7.1 Responsibility for assets 

A.9.2 Equipment security 

A.10.7 Media handling

A.10.8 Exchange of information

Media Encryption Specifications

Check Point Media Encryption Specifications

Ports Controlled

Check Point Media Encryption Ports Controlled

Devices Controlled

Check Point Media Encryption Devices Controlled

ntegra-delivering-the-right-solutions-with-CastleForce 

Using the ntegra Media Encryption deployment solution ensures best practices are fully exploited, providing a solid foundation to ensure your encryption and security requirements are met without business disruption

Deployment of Check Point Media Encryption needs to be carefully planned because:

  • You need a smooth roll out, minimising disruption to users
  • Impact on support overheads need to be kept to a minimum within the organisation
  • Unplanned scenarios could preclude to at least excessive support overheads, if not actual loss of data

Check Point Media Encryption Technical solution overview Datasheet