Encryption is a method of securing data by scrambling the bits of a computer's files so that they become illegible. The only method of reading the encrypted files is by decrypting them with a key; the key is unlocked with a password.
Benefits
Whole disk encryption protects everything on a disk drive – including the operating system – as well as USB flash and other external drives. Even files you may not know about that keep exact copies of data that you've been working on, such as temporary files are encrypted.
Related software
PGP Desktop: Chosen by IS&T to protect MIT's high-risk data on a Windows-based PC
FileVault for Mac: Whole disk encryption functionality built into OS X
Encryption on mobile devices: for smaller devices, such as a tablet or smartphone, data can be encrypted using built-in security software. Each device handles this differently, so you will want to check with the manufacturer's user manual
Key features
- Only protects the data when the machine or device is turned off, or you have logged off
- Most useful on machines or peripherals that are likely to be lost or stolen (e.g., laptops and USB drives), but can be installed on desktops as well
- Offers no protection for malware (computer virus) infections
- Protects the information on the device with a login password
- PGP Desktop uses key escrow to decrypt if a password is lost or forgotten
- Users should remember to save the password in a safe place
Requirements
MIT certificates to download PGP.
Getting started
-
Read the Encryption at MIT article in the Knowledge Base to learn about the options and recommendations.
If you are unsure whether you should be using whole disk encryption for compliance with data security regulations, contact IS&T via infoprotect@mit.edu. -
Start using the software
Windows: Download a copy of PGP Desktop from the Software Grid or obtain a copy through your desktop support staff. Students are not licensed to access the free download.
PGP Desktop 10 Whole Disk Encryption is provided for individuals who need to protect sensitive information on laptops and portable storage devices against physical loss or theft. PGP Desktop is offered to faculty, staff, affiliates, researchers, and graduate students who handle sensitive information in key, high-risk areas at MIT.Mac: Enable FileVault on OS X Lion or Mountain Lion. These links guide you through the set-up process.
Mobile devices: View the Mobile Device Ninja to find out about enabling encryption on your mobile device.
- Contact the IS&T Help Desk for assistance with any of the above-listed options.
