DriveLock Features
Compare DriveLock to similar security solutions and you'll quickly realize that DriveLock not only includes all protection mechanisms they do, but it also adds unique features that no competitor can match. DriveLock makes it easy to centrally control the protection of your data, without requiring additional servers.
Quick Links:
» Core Protection: Drives and Devices
» Removable Media Encryption - DriveLock Encryption 2-Go
» Full Disk Encryption
» Reports and Auditing
» Application Launch Filter (Application Control)
» Administration
» System Requirements
Core Protection: Drives and Devices
- Remote detection of all removable devices that have been used; no Agent installation is required. Scan results can be used to easily add approved drives and devices to whitelists.
- Dynamic, configurable locking of removable drives and media (USB memory sticks, floppy disks, CD-ROM, SD cards, eSATA disks, etc.)
- Controls the use most types of devices (Bluetooth, Palm, Windows Mobile, BlackBerry smartphones, card readers, imaging devices, network adapters, modems, sound, video and game controllers, cameras, printers and many more)
- Locks most types of ports, including USB controllers, 1394/Firewire controllers, PCMCIA controllers, infrared controllers, serial (COM) and parallel (LPT) ports
- Configurable whitelists to allow access to devices (device type or device model)
- Specific storage devices can be controlled based on their serial numbers
- Separate access lists can be defined for individual devices or group of devices
- Access can be granted to selected users and groups
- Fully integrated with Active Directory and Group Policy
- Also supports most other network operating systems, including Novell NetWare and Linux
- Policy enforcement dynamically adjusts permissions based on the currently logged-on user
- Assign drive letters to removable drives to avoid conflicts with network drives
- File filters to allow or deny coping of specific file types
- Auditing of which files are read from or written to removable drives
- Shadowing of files keeps a full record of the content of files that are copied to or from removable drives
- Separate configuration of read and write access for removable drives
- Drive access rules can be based on drive size or encryption status
DriveLock Encryption 2-Go
- Encrypt data with state-of-the-art encryption (up to 256-bit encryption strength)
- Choice of industry-standard encryption algorithms (AES, 3DES, Blowfish, etc.)
- FIPS 140-2 validated encryption algorithms available
- Encrypt data on mobile devices or hard disks
- Automatic and transparent encryption of data copied to mobile devices
- Wizard for burning encrypted CDs and DVDs
- Ability to decrypt data on computers without requiring installation of DriveLock
- DriveLock Mobile for encrypting data on Windows Mobile devices
- Secure deletion of single files, directories or entire disks to prevent data disclosure
- Safe recovery of containers when encryption password is lost (online and offline)
Full Disk Encryption
- Encrypt entire hard drives, including system partition
- FIPS140-2 encryption
- Pre-boot authentication with single sign-on
- Mature tools to decrypt damaged drives
- One-time logon options for users who forgot their logon password
- Support for token and smartcard logon
- Central administration and monitoring of encryption status
Reports and Auditing
- DriveLock Control Center: a central reporting console for all DriveLock events
- Build extensive reports based on collected data
- Multiple alerting mechanisms for DriveLock events
- Forensic data analysis inclcuding data drill-down capabilities
Application Launch Filter (Application Control)
- Comprehensive control over who can start which programs
- Flexible combination of whitelists and blacklists
- Auditing of all application usage
- Easy administration of allowed applications using application hash databases, file ownership or software certificates
- Online hash database with millions of application hash values
Administration
- All configuration is done using a Microsoft Management Console (MMC) snap-in
- Starter Mode and advanced configuration for fast and secure deployment
- Device Scanner allows you to find out which devices are or were ever connected to all computers in your network and simplifies the creation of rules
- Easy client deployment using Group Policy or other software deployment system
- Central configuration using Active Directory and Group Policy
- Alternate configuration mechanism using configuration files via UNC path, HTTP or FTP
- Supports Group Policy Management Console (GPMC) and NetIQ Group Policy Administrator
- Remote connection to client computers to temporarily unlock devices and to troubleshoot policy enforcement
- Remote identification of devices connected to clients
- Quick policy deployment using templates for common computer models (Dell, HP, IBM, etc.)
- Deployment Wizard
- Customizable taskbar notification with HTML text formatting
- Multilingual user interface (MUI), supporting 6 languages, more to be added soon
- Anti-tampering mechanisms, such as an optional password for uninstalling DriveLock, to prevent unauthorized disabling of the system protection
System Requirements
- Windows 7, Windows Vista, Windows XP SP2
- Windows Server 2003 SP1 or later, Windows 2008 or later
- Active Directory with Group Policy recommended for central configuration








