Specifications
Endpoint Encryption for Files and Folders Policy Settings
| 45
With this option, it is possible to have the original time values restored (preserved)
after encryption and decryption, e.g. the Last Modified time will be reset to when the
file was truly last modified, i.e. by a user. The default setting is enabled.
Require authentication for listing of encrypted folders
This setting prevents a user from listing (view) the contents of an encrypted folder
unless the user has access to the encryption key used to encrypt that folder.
The Endpoint Encryption for Files and Folders client must be installed for this viewing
restriction to occur. The default value is disabled.
Use wiping when encrypting and deleting files
When a file is encrypted with Endpoint Encryption for Files and Folders there is a risk
that plaintext traces may remain on the disk. With the wiping functionality that is
enabled with this option, any plaintext traces are securely deleted (wiped) whenever a
file is encrypted. When using wiping, the encryption of files will take about 5% longer
than without wiping.
The wiping mechanism follows the data shredding specification of US Department of
Defense (DoD). The specification detail may be found in:
DoD 5220.22-M National Industrial Security Program Operating Manual (NISPOM)
January 1995, Department of Defense & Central Intelligence Agency, U.S. Government
Printing Office. ISBN 0-16-045560-X.
Enable limiting of file size that will be encrypted
Marking this option allows you to exclude files larger that a certain size from
encryption when encrypted by a folder policy enforcement, i.e. when existing files are
encrypted in accordance with the folder policy (including Removable Media existing
content enforcement). Files encrypted with explicit (right-click) Encrypt… are not
subject to this limitation, nor are files encrypted by a file extension encryption policy;
Other files not subject to this limitation are files that are drag-dropped to encrypted
folders and files saved to encrypted folders. Specify the file size restriction in the field.
You can use this option to prevent (very) large files from being encrypted by the policy
enforcement; particularly for network shares where encryption of large files may cause
heavy network traffic.
I/O Utilization
This value defines the frequency at which Endpoint Encryption for Files and Folders will
encrypt files when enforcing encryption policies. A value of 50% means it will take a
file, encrypt it and then wait the same amount of time it took to encrypt the previous
file before starting to encrypt the next file.