Lenovo ThinkPad X1 (English) User Guide - Page 77

Hard disk security, Setting the security chip

Page 77 highlights

Hard disk security Your computer supports an enhanced security solution for solid state drive or hard disk drive. To protect passwords from unauthorized security attacks, several of the latest technologies and algorithms are integrated into UEFI BIOS and hardware design of ThinkPad notebooks. To maximize security, do the following: 1. Set a power-on password as well as a hard disk password for your internal solid state drive or hard disk drive. Refer to the procedures in "Power-on password" on page 56 and "Hard disk passwords" on page 57. For security, a longer password is recommended. 2. To provide reliable security for UEFI BIOS, use the security chip and a security application with a Trusted Platform Module management feature. Refer to "Setting the security chip" on page 61. 3. If a Disk Encryption hard disk drive or an Encryption solid state drive is installed in your computer, be sure to protect the contents of your computer memory from unauthorized access by use of drive encryption software, such as Microsoft Windows BitLocker® Drive Encryption in Windows 7. Refer to "Using Windows BitLocker Drive Encryption" on page 61. 4. Before you dispose of, sell, or hand over your computer, make sure to delete data stored on it. Refer to "Notice on deleting data from your hard disk drive or solid state drive" on page 66. Note: The hard disk drive built into your computer can be protected by UEFI BIOS. Using Windows BitLocker Drive Encryption To help protect your computer from being subject to unauthorized access, be sure to use drive encryption software, such as Windows BitLocker Drive Encryption. Windows BitLocker Drive Encryption is an integral security feature of Windows 7. It is supported in Ultimate and Enterprise editions of Windows 7. It can help you protect the operating system and data stored in your computer data, even if your computer is lost or stolen. BitLocker works by encrypting all user and system files, including the swap and hibernation files. BitLocker uses a Trusted Platform Module to provide enhanced protection for your data and to ensure early boot component integrity. A compatible TPM is defined as a V1.2 TPM. To check the BitLocker status, click Start ➙ Control Panel ➙ System and Security ➙ BitLocker Drive Encryption. For details about Windows BitLocker Drive Encryption, go to the Help and Support for Windows 7, or search for "Microsoft Windows BitLocker Drive Encryption Step-by-Step Guide" on the Microsoft web site. Disk Encryption hard disk drive and Encryption solid state drive Some models contain the Disk Encryption hard disk drive or Encryption solid state drive. This feature helps to protect your computer against security attacks on media, NAND flash or device controllers by use of a hardware encryption chip. For the efficient use of the encryption feature, be sure to set a hard disk password for the internal storage device. Setting the security chip Strict security requirements are imposed on network client computers that transfer confidential information electronically. Depending on the options you ordered, your computer might have an embedded security chip, a cryptographic microprocessor. With the security chip and Client Security Solution, you can do the following: • Protect your data and system Chapter 4. Security 61

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181

Hard disk security
Your computer supports an enhanced security solution for solid state drive or hard disk drive. To protect
passwords from unauthorized security attacks, several of the latest technologies and algorithms are
integrated into UEFI BIOS and hardware design of ThinkPad notebooks.
To maximize security, do the following:
1. Set a power-on password as well as a hard disk password for your internal solid state drive or hard disk
drive. Refer to the procedures in “Power-on password” on page 56 and “Hard disk passwords” on page
57. For security, a longer password is recommended.
2. To provide reliable security for UEFI BIOS, use the security chip and a security application with a Trusted
Platform Module management feature. Refer to “Setting the security chip” on page 61.
3. If a Disk Encryption hard disk drive or an Encryption solid state drive is installed in your computer,
be sure to protect the contents of your computer memory from unauthorized access by use of drive
encryption software, such as Microsoft Windows BitLocker
®
Drive Encryption in Windows 7. Refer to
“Using Windows BitLocker Drive Encryption” on page 61.
4. Before you dispose of, sell, or hand over your computer, make sure to delete data stored on it. Refer to
“Notice on deleting data from your hard disk drive or solid state drive” on page 66.
Note:
The hard disk drive built into your computer can be protected by UEFI BIOS.
Using Windows BitLocker Drive Encryption
To help protect your computer from being subject to unauthorized access, be sure to use drive encryption
software, such as Windows BitLocker Drive Encryption.
Windows BitLocker Drive Encryption is an integral security feature of Windows 7. It is supported in Ultimate
and Enterprise editions of Windows 7. It can help you protect the operating system and data stored in your
computer data, even if your computer is lost or stolen. BitLocker works by encrypting all user and system
files, including the swap and hibernation files.
BitLocker uses a Trusted Platform Module to provide enhanced protection for your data and to ensure early
boot component integrity. A compatible TPM is defined as a V1.2 TPM.
To check the BitLocker status, click
Start
Control Panel
System and Security
BitLocker Drive
Encryption
.
For details about Windows BitLocker Drive Encryption, go to the Help and Support for Windows 7, or search
for “Microsoft Windows BitLocker Drive Encryption Step-by-Step Guide” on the Microsoft web site.
Disk Encryption hard disk drive and Encryption solid state drive
Some models contain the Disk Encryption hard disk drive or Encryption solid state drive. This feature
helps to protect your computer against security attacks on media, NAND flash or device controllers by use
of a hardware encryption chip. For the efficient use of the encryption feature, be sure to set a hard disk
password for the internal storage device.
Setting the security chip
Strict security requirements are imposed on network client computers that transfer confidential information
electronically. Depending on the options you ordered, your computer might have an embedded security chip,
a cryptographic microprocessor. With the security chip and Client Security Solution, you can do the following:
Protect your data and system
Chapter 4
.
Security
61