DOD mandates data encryption for mobile devices

DOD data-at-rest encryption policy for mobile devices (.pdf)

Pentagon officials must ensure certain data stored on mobile devices is encrypted in compliance with the National Institute of Standards and Technology's Federal Information Processing Standard 140-2, according to a new Defense Department policy.

The policy, signed on July 3 by Pentagon Chief Information Officer John Grimes, mandates that all unclassified data not approved for public release should be treated as sensitive and must be encrypted. The policy does not apply to information cleared for public release.

The term mobile devices describes laptop PCs and personal digital assistants, as well as removable storage media, like thumb drives and compact discs, Grimes wrote in a memo to senior Defense Department leaders.

The policy instructs Pentagon officials to pay particular attention to the encryption of mobile devices used by senior DOD officials, like flag officers and senior executives, who travel frequently outside the continental United States. According to Grimes, the loss or theft of mobile devices storing U.S. defense information abroad is especially severe.

The FIPS 140-2 specification was approved in 2001 and grew out of Federal Standard 1027, General Security Requirements for Equipment, which used the now-outdated Data Encryption Standard. NIST is now working on the next iteration, FIPS 140-3.

Featured

  • Contracting
    8 prototypes of the border walls as tweeted by CBP San Diego

    DHS contractors face protests – on the streets

    Tech companies are facing protests internally from workers and externally from activists about doing for government amid controversial policies like "zero tolerance" for illegal immigration.

  • Workforce
    By Mark Van Scyoc Royalty-free stock photo ID: 285175268

    At OPM, Weichert pushes direct hire, pay agent changes

    Margaret Weichert, now acting director of the Office of Personnel Management, is clearing agencies to make direct hires in IT, cyber and other tech fields and is changing pay for specialized occupations.

  • Cloud
    Shutterstock ID ID: 222190471 By wk1003mike

    IBM protests JEDI cloud deal

    As the deadline to submit bids on the Pentagon's $10 billion, 10-year warfighter cloud deal draws near, IBM announced a legal protest.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.