Compare DriveLock to similar security solutions and you'll quickly realize that DriveLock not only includes all protection mechanisms they do, but it also adds unique features that no competitor can match. DriveLock makes it easy to centrally control the protection of your data, without requiring additional servers.
Remote detection of all removable devices that have been used; no Agent installation is required. Scan results can be used to easily add approved drives and devices to whitelists.
Dynamic, configurable locking of removable drives and media (USB memory sticks, floppy disks, CD-ROM, SD cards, eSATA disks, etc.)
Controls the use most types of devices (Bluetooth, Palm, Windows Mobile, BlackBerry smartphones, card readers, imaging devices, network adapters, modems, sound, video and game controllers, cameras, printers and many more)
Locks most types of ports, including USB controllers, 1394/Firewire controllers, PCMCIA controllers, infrared controllers, serial (COM) and parallel (LPT) ports
Configurable whitelists to allow access to devices (device type or device model)
Specific storage devices can be controlled based on their serial numbers
Separate access lists can be defined for individual devices or group of devices
Access can be granted to selected users and groups
Fully integrated with Active Directory and Group Policy
Also supports most other network operating systems, including Novell NetWare and Linux
Policy enforcement dynamically adjusts permissions based on the currently logged-on user
Assign drive letters to removable drives to avoid conflicts with network drives
File filters to allow or deny coping of specific file types
Auditing of which files are read from or written to removable drives
Shadowing of files keeps a full record of the content of files that are copied to or from removable drives
Separate configuration of read and write access for removable drives
Drive access rules can be based on drive size or encryption status
Encrypt data with state-of-the-art encryption (up to 256-bit encryption strength)
Choice of industry-standard encryption algorithms (AES, 3DES, Blowfish, etc.)
FIPS 140-2 validated encryption algorithms available
Encrypt data on mobile devices or hard disks
Automatic and transparent encryption of data copied to mobile devices
Wizard for burning encrypted CDs and DVDs
Ability to decrypt data on computers without requiring installation of DriveLock
DriveLock Mobile for encrypting data on Windows Mobile devices
Secure deletion of single files, directories or entire disks to prevent data disclosure
Safe recovery of containers when encryption password is lost (online and offline)
Encrypt entire hard drives, including system partition
FIPS140-2 encryption
Pre-boot authentication with single sign-on
Mature tools to decrypt damaged drives
One-time logon options for users who forgot their logon password
Support for token and smartcard logon
Central administration and monitoring of encryption status
DriveLock Control Center: a central reporting console for all DriveLock events
Build extensive reports based on collected data
Multiple alerting mechanisms for DriveLock events
Forensic data analysis inclcuding data drill-down capabilities
Comprehensive control over who can start which programs
Flexible combination of whitelists and blacklists
Auditing of all application usage
Easy administration of allowed applications using application hash databases, file ownership or software certificates
Online hash database with millions of application hash values
All configuration is done using a Microsoft Management Console (MMC) snap-in
Starter Mode and advanced configuration for fast and secure deployment
Device Scanner allows you to find out which devices are or were ever connected to all computers in your network and simplifies the creation of rules
Easy client deployment using Group Policy or other software deployment system
Central configuration using Active Directory and Group Policy
Alternate configuration mechanism using configuration files via UNC path, HTTP or FTP
Supports Group Policy Management Console (GPMC) and NetIQ Group Policy Administrator
Remote connection to client computers to temporarily unlock devices and to troubleshoot policy enforcement
Remote identification of devices connected to clients
Quick policy deployment using templates for common computer models (Dell, HP, IBM, etc.)
Deployment Wizard
Customizable taskbar notification with HTML text formatting
Multilingual user interface (MUI), supporting 6 languages, more to be added soon
Anti-tampering mechanisms, such as an optional password for uninstalling DriveLock, to prevent unauthorized disabling of the system protection
New: DriveLock's state-of-the-art virus protection is controlled and monitored using a central console. This includes some of the most advanced methods for antivirus and antispyware technologies (heuristics and behavior-based detection) as well as proactive defense against malicious software that keeps constantly changing itself to evade detection (polymorphic malware).
With its completely integrated Commtouch® antivirus engine, DriveLock delivers the following benefits:
The integrated virus protection can block all access to external storage devices and media when malicious software has been detected and only allow access again once the malware has been removed. This integration provides much better security than external antivirus software because the DriveLock virus scanner can scan any external media for malware before ever giving access to a user. This happens lightning-fast so users don't even notice the added protection.
Windows 7, Windows Vista, Windows XP SP2
Windows Server 2003 SP1 or later, Windows 2008 or later
Active Directory with Group Policy recommended for central configuration