
Check Point Media Encryption secures sensitive corporate data and blocks incoming malware by encrypting removable media such as USB storage devices, CDs and DVDs and controlling activity (read, write and execute) on ports and devices. All device content is automatically encrypted in the background for a transparent end-user experience. Unique to Check Point, users can access encrypted media securely on unmanaged computers with no client installation. As the only device and port control solution integrated with a single endpoint security agent, Check Point Media Encryption simplifies compliance and reduces administrative overhead. Now supports Windows 7.
5 Virusn5 SpywarenX SpamnX Web/IMn5 IPS/Patch Mgmtn5 Data/System Mgmtn
Encrypts information stored on devices and removable media — Encryption Policy Manager allows users to encrypt devices and removable media using strong algorithms including 256-bit AES. Uniquely, Encryption Policy Manager can be configured to allow secure access to encrypted media when using unmanaged computers, such home or business center PCs. Alternatively, users may install a plug-in to enable device access from unmanaged PCs.
Protects corporate information and endpoint PCs by controlling which devices can be accessed and which ports can be used — Device Manager controls access to removable devices, such as USB flash drives, CD/DVD drives, Smartphones, and PDAs. Access can be managed using a whitelist or blacklist, or defined at a granular level by type, brand, size, or ID. Assign unique serial numbers to devices for more granular management options. Device Manager can also enable/ disable individual PC ports, such as USB, FireWire, Bluetooth, WiFi and LPT.
Ensures that changes made to information stored on devices are authorized by the user — Removable Media Manager places a unique digital signature on each encrypted device, and whenever device contents are altered, the digital signature is updated. If the contents have been altered using a computer which does not have Media Encryption installed, the user must re-authorize the device before it can be used in the protected environment. Using DataScan (see below) and antivirus software, Removable Media Manager can also force devices to be scanned for malware before granting access.
Prevents undesirable files, such as executables and malware, from entering endpoints through ports — DataScan can block or allow transfer of specific file types, as determined by extension and internal file structure, and block access to devices until dangerous or prohibited files have been deleted.
Safeguards information and endpoints by preventing users from creating, modifying or deleting specific file types — administrators can define protected files by extension and create exceptions for modification of files by trusted applications.
Simplifies compliance audits and event notification — unlike other solutions, Media Encryption stores logs to a central database, enabling easy creation of detailed reports using structured queries. Administrators can also centrally monitor and audit file operations on removable devices, such as which files were moved to or from individual devices, and when. Email alerts can be configured to notify administrators about specific events.
Check Point Media Encryption datasheet
Requirement 3: Protect stored cardholder data
Protecting Stored Cardholder Data
GCSX No 10 Mobile / Home Working
A.7.1 Responsibility for assets
A.10.8 Exchange of informationMedia Encryption Specifications
Ports Controlled
Devices Controlled
Using the ntegra Media Encryption deployment solution ensures best practices are fully exploited, providing a solid foundation to ensure your encryption and security requirements are met without business disruption
Deployment of Check Point Media Encryption needs to be carefully planned because:
© Copyright Castleforce 2007-2012. Web design by Theme Group