General network and computer security: keyservers, PGP/GPG, encryption, etc...book/instructional recommendations?
I am trying to come up with some constructive suggestions regarding how to improve and automate security protocols at work. I have some basic ideas but know very little about it from an implementation standpoint. I use PGP, GPG, and Zip AES to encrypt and decrypt individual files but that's the limit of my experience.
I'm wondering what the 'industry standards' are for something like having a non-networked computer acting as a keyserver, into which say I'd plug a USB memory stick (or 'smart card') each day, receive a random password, which would then allow me to login to a networked computer, on which everything is encrypted with something like GPG. And how effective/efficient are biometric/fingerprint scanners?
This is in a Windows environment...I'm reading about Microsoft's
Encrypting File System right now, which sounds like it would work for encrypting folders...that's the sort of recommendation I'm basically looking for (since I don't know exactly what I'm looking for;).
posted by tracert at 5:20 PM on March 10, 2008