D
D
danykeep2015-09-03 13:10:28
Information Security
danykeep, 2015-09-03 13:10:28

How to prevent booting from live media?

Actually a hole in the security of most organizations: booting from live media. In practice, it turned out to be insufficient to set a password on the BIOS, since some of them automatically set the connected devices first at boot.
Is there any unified way to protect, other than picking every BIOS?

Answer the question

In order to leave comments, you need to log in

4 answer(s)
S
Sergey Kovalev, 2015-09-03
@Sergey-S-Kovalev

Unfortunately, you can't do without picking the BIOS on a PC.
In the selection of boot devices, specify the specific device from which you want to boot.
In advanced settings, disable the ability to boot from USB/PCI/LAN devices.
Password on the BIOS, sealing the system unit, as a "guarantee" against opening and resetting by closing contacts.

V
Vladimir Martyanov, 2015-09-03
@vilgeforce

Physically closing USB ports and disabling CD-ROMs.

M
mace-ftl, 2015-09-03
@mace-ftl

To be stunned, colleagues - yes, the method of minimizing this risk is the ENCRYPTION of the disk stupidly. By the way, it also covers the risk of "they will take away the disk", since your attacker already has physical access to the PC

D
DrLabRus, 2015-09-03
@DrLabRus

It all depends on your needs/budget.
For example, there is this (and with certificates from whom you need and with the corresponding price, including): Trusted Boot Hardware Module (AMDZ)

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question