NIST 800-171 Rev 3 Changes: What They Mean for MSP Clients
NIST Special Publication 800-171 defines the security requirements for protecting Controlled Unclassified Information in non-federal systems. It's...
Protecting critical data across all PCs, mobile devices, and USBs is a 24/7/365 responsibility. Bad actors don’t take breaks—you need a managed device security solution that works around the clock for you. RiskResponder™ is built to do just that. What protections do you need in place when environmental or behavioral risks exceed acceptable thresholds?
The BeachheadSecure cloud-based platform provides a straightforward and intuitive way to manage encryption, remote data access control, endpoint security, and more—for all of your critical business devices and data.
Customer-managed BeachheadSecure® can be purchased as a pre-paid subscription in either one or three-year terms to qualifying businesses. Contact Beachhead sales for more information.
Trained Beachhead-authorized reseller partners offer BeachheadSecure as a monthly managed service, often with a co-managed (CoMITs) option available.
Explore our growing library of resources including sales sheets, white papers, and more. While you're at it—stay up to date on the latest cyber threats and security trends.
BeachheadSecure v6.11.1 is now available.
The headline is ScreenLock, a new quarantine response that works regardless of the encryption method on the device and restores access without a 48-character BitLocker recovery key. This release also expands MFA policy control, consolidates BitLocker management into a single action, and adds scheduled compliance reporting.
Below is the complete list of changes:
Let's dig in to each of the core feature updates/releases.
A new ScreenLock response is available in RiskResponders for PCs and Macs. It can be triggered manually as a quarantine action or automatically through a RiskResponders policy.
ScreenLock immediately prevents an unauthorized user from accessing the computer, even one with valid login credentials, and can be used regardless of the encryption method in place. It is a particularly simple alternative for computers using BitLocker-only encryption, because access can be restored without requiring the user to enter a 48-character BitLocker recovery key.
To restore access, select the computer from the Computer Listing and click Restore from Quarantine. ScreenLock is removed the next time the computer checks in. Alternatively, select the computer and choose More Actions > Recovery Code, then give the user the code to enter directly into the ScreenLock dialog.
Action required: The ScreenLock action is added in a disabled state to RiskResponders wherever a "Revoke access to EFS encrypted files" action already exists. An administrator needs to turn the action on for it to take effect.
A note on choosing a quarantine response: Quarantining a device is an effective way to protect data from exposure, but the response needs to match the encryption method in use. Revoke Access to EFS Encrypted Files, for example, will not provide effective protection on devices that are not using EFS encryption. Contact Beachhead Support with questions about selecting the right quarantine response for your environment.
Administrators can now reset MFA for another administrator. Resetting MFA turns it off for the next login.
To reset MFA, go to the administrator listing page, select the checkbox next to the administrator whose MFA should be reset, and select Reset MFA.
The "Suspend BitLocker" menu item has been replaced with Manage BitLocker. After selecting a computer, click Manage BitLocker to open a pop-up with three actions:
The BitLocker tab UI has been modified to make management simpler.
Recovery keys and Secure Decommission keys have been moved into separate tables. In the Volumes table, the primary key protector for the OS drive now shows only the protector type in the Type column.
The BitLocker Recovery listing has also been modified so that it lists only Recovery Keys and Secure Decommission Keys.
An indicator has been added to the ComplianceEZ page showing whether a BHS-provided implementation satisfies or partially satisfies a control.
A Last Modified column has also been added to track when changes were made to each control.
Report scheduling has been added for ComplianceEZ. Go to the ComplianceEZ page, click Output Report, and select Schedule Report. A report creation pop-up opens where you can set the schedule, recipient emails, and report options. Click OK to schedule the report.
New data locations have been added for EFS targeting, along with additional file types.
The server now generates alerts when an install fails during the install web call. For example, an alert is generated if there are not enough licenses or if a computer with the same name already exists.
The MFA policy can now be applied to all users, domain users, or local users. Apply the policy from the Authentication Policies section on the RiskResponders page. By default, the MFA policy applies to all users.
Administrators can require a setup code before allowing users to set up MFA.
To configure one, go to the RiskResponders page and expand the Authentication Policies section. In the Multifactor Authentication (MFA) settings, change Multifactor Authentication to Mandatory, select Yes for MFA Setup Code, and enter a code.
Administrators are responsible for communicating the setup code to users, since it is required to set up MFA. If MFA is not set up, the computer cannot be used.
Note: This feature is currently PC-only. It will be added to the Mac agent in a future release.
The server now retrieves the latest Mac and PC OS versions and indicates whether each computer is up to date. OS version numbers appear in the OS Build column on the computer listing page. If a computer is not running the latest OS version, the OS Build text is highlighted; clicking the highlighted text opens an information pop-up with update details.
Reports have been updated to include Location. The EFS Encryption Status check in the Compliancy report has also been updated to verify that EFS is actually being used on the computer.
Attaching to and detaching from accounts has changed. Instead of attaching to an account, an administrator now manages an account.
Contact Beachhead Support for help choosing the right quarantine response for your encryption method, or for guidance on rolling out MFA setup codes across your environment.
Learn more at: https://www.beachheadsolutions.com/device-security-encryption
The latest cybersecurity, encryption, and threat intel—delivered straight to your inbox.
NIST Special Publication 800-171 defines the security requirements for protecting Controlled Unclassified Information in non-federal systems. It's...
Multi-factor authentication and encryption are the two highest-impact changes in the updated HIPAA Security Rule. Both were previously...
One of the most common questions MSPs hear from defense contractor clients: "Do we need a formal assessment, or can we self-assess?" The answer...