What equipment should be encrypted?
The following registry-owned equipment used to process or store PII should be encrypted— • Laptops and tablet PCs. • Desktop computers, if they are considered to be at a high risk for theft or misuse. • Portable electronic media, such as USB flash drives, thumb drives, external hard drives, and personal digital assistants. Note: Vendor-owned equipment is subject to the same security requirements as that owned by federal employees. Registry policy must include a key recovery process for all encrypted registry data.