Protecting sensitive files on a Windows file server



We are looking for a secure way to store very sensitive files on our
Windows servers. The data is shared. We will turn on full auditing,
create hidden shares and a security group.

Which type of protection would be most suitable:

Office 2003 encryption
Windows EFS
Winzip 9.x encrypted archives
RSA SecurID Windows Agent (2 factor authentication)
PGP Desktop Pro

Our concern with the Windows/Office encryption types is that it could
be cracked - ie. someone could get hold of the file and run some kind
of password recovery on the file and access the data.

Any ideas on how to approach this would be much appreciated.



Relevant Pages

  • Re: user does not have acces privileges
    ... to reinstall the windows to do that. ... ownership is the reason of the inaccessibility. ... I'm not an expert but I find out, it is not the encryption but ... "Zorro" wrote: ...
    (microsoft.public.windowsxp.accessibility)
  • Re: user does not have acces privileges
    ... But now at the new files I should have the right EFS key in my computer. ... That means there is something wrong with the ownership settings and that was ... Or it is only matter if the encryption is combined with the ownership change? ... to reinstall the windows to do that. ...
    (microsoft.public.windowsxp.accessibility)
  • Re: Cannot access encrypted files after reinstalling Windows XP Professional
    ... able to break the encryption in a reasonable amount of time. ... > keys are generated each time you do an install, ... > they would be related to the Windows serial key, ... >>> All data files are stored on partition D:. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Windows Server 2003 - Not secure from my test but OSX from Mac is secure from the start
    ... When enabled in mode 3 you can store the system encryption key ... Sadly most Windows admins are not fully aware of all the security tools ... Worms & Port Scans ...
    (Security-Basics)
  • Re: "Rule 30" CA encryption implementation
    ... never ever let the plaintext touch the hard disk. ... You should use a disk encryption program and not a file encryption ... Windows user so haven't kept track. ... laptops for work or something like that (company managers get laptops ...
    (sci.crypt)