External File System Encryption Level IT policy rule

Description

This rule specifies the level of encryption that a BlackBerry device uses to encrypt files that it stores on a media card. You can use this rule to require that the device encrypts a media card, either including or excluding media-card files. You cannot use this rule to encrypt files that a BlackBerry device user transfers to the media card manually (for example, from a USB mass storage device).

The master keys for the media card are stored on the media card. A device is designed to use the master keys to decrypt and encrypt files on the media card. A device is designed to use the device key, a user-provided password, or both to encrypt the master keys.

Possible values

  • Encrypt to User Password (excluding multimedia directories)
  • Encrypt to User Password (including multimedia directories)
  • Encrypt to Device Key (excluding multimedia directories)
  • Encrypt to Device Key (including multimedia directories)
  • Encrypt to User Password and Device Key (excluding multimedia directories)
  • Encrypt to User Password and Device Key (including multimedia directories)
  • Not required

Default values

  • Encrypt to User Password (excluding multimedia directories) in the Advanced Security IT policy and Advanced Security with No 3rd Party Applications IT policy
  • Not required in all other preconfigured IT policies

Minimum requirements

  • BlackBerry Device Software 4.2

Rule introduction

  • BlackBerry Enterprise Server 4.0 SP6