Data Encryption
Definition
Encryption is a method of scrambling data so that only someone who possesses the appropriate password or “key” can access the information. Encryption can be a confusing subject because there are so many different types of encryption that can be used to protect data. Currently, the most desirable type of encryption is called AES (Advanced Encryption Standard). AES encryption is available in different strengths, expressed in “bits”—the more bits, the stronger the encryption. The current US government standard for data encryption is 256-bit AES encryption.
WinZip – Encryption Software
WinZip is an application familiar to many people for its ability to compress the size of data files. The licensed version of WinZip 10 Standard can encrypt files using 256-bit AES encryption. Although ECU does not have a site license for WinZip 10 Standard, the application is recommended and supported by ITCS. WinZip Standard Edition can be purchased and downloaded from the WinZip website in single-user or multi-user licensing formats.
Encrypt Sensitive Data
If you have sensitive data stored on a workstation or (especially) a laptop computer, you should encrypt the sensitive data to protect it from unauthorized access or theft. Flash drives, also known as thumb drives, are popular for transporting data between computers. Sensitive data stored on flash drives should be encrypted using 256-bit AES encryption. Some flash drive manufacturers like SanDisk include an encryption program with some of their flash drives. The encryption program can be used to divide the storage on the flash drive into two areas of variable sizes—one area for encrypted data and one for unencrypted data.
Email
Email is not considered a secure method of communication. However, if you must send sensitive information via email:
-
Encrypt the data.
-
Include the data in an email as an attachment
-
Send the password required to decrypt (open) the encrypted data to the recipient under separate cover (e.g., another email, telephone call).
-
The recipient will also require a licensed copy of WinZip to decrypt the encrypted data.