IT Security Policy
All Whisper’s desktop and laptop computers (including any computers not owned by Whisper but used routinely for Whisper business) should have:
- full disk encryption requiring a password at boot time. If the computer is lost or stolen, this prevents anybody from gaining access to the data on the computer, provided the computer is screenlocked (closing the lid or not using it for a while will normally lock the screen), hibernating or switched off at the time it’s lost or stolen.
- regular backups to an encrypted backup device. This protects against accidental deletion, loss, theft and physical damage e.g. fire, water, being dropped.
Suitable encryption programs are:
- Truecrypt 7.1a for Windows, MacOS and Linux. The commercial fork Veracrypt currently takes too long (about 1 minute) to verify the boot password so Truecrypt 7.1a should be used instead; this might change when a UEFI version of Veracrypt is released.
- Microsoft’s Bitlocker for Windows (available on certain versions of Windows only)
- Apple’s FileVault, the native encryption tool on MacOS. Instructions for setting up FileVault are here: https://support.apple.com/en-us/HT204837.