-
Couldn't load subscription status.
- Fork 2
First pass traveling page #10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
src/traveling.md
Outdated
| ### Physical | ||
|
|
||
| 1. You MUST NEVER leave a device unlocked AND unattended. | ||
| 1. You MUST use full disk encryption on any device which supports it. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We should be recommending this somehwere else (eg work devices)? or similar?
And here just refer to it.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The work devices page is geared specifically towards laptops with EDR; aren't those going to be distributed already configured for use?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Correct, but not everyone in the ecosystem will have that.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
So should I add a section to work_devices.md after EDR that discusses non-EDR ways of hardening laptops? What other than full disk encryption would be part of that section?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I could also add a quick note about full disk encryption inside the "Deploying hardened laptops" subsection, if we don't have enough for a full section
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yeah I think we can just say full-disk encryption and "strong" password (eg linking to some nist policy)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
…tion on network attacks relating to travel
…page, and link from travel page
…page, and link from travel page
No description provided.