CUMC Home | Columbia University | Jobs at CUMC | Contact CUMC | Find People
Columbia University Medical Center logo,  Columbia University Medical Center Information Technology
For support: call extension 5-Help (212-305-4357) or email us

Encryption Recommendations

The recommendations on this page are provided as a courtesy only, anyone requiring further assistance with the installation, use and troubleshooting of any software and hardware at CUMC should refer to the Computer Support page.
Full information on Encryption requirements at CUMC can be found within the IT Policies, Procedures and Guidelines area of our website.

Before Using Any Encryption Program
The purpose of any encryption software is to make data unreadable if proper authentication is not provided. Issues including permanent loss of data can occur if you do not adequately prepare your computer and data before installing or beginning to use encryption.
  1. Verify that the software is compatible with your computer and existing software.
  2. Review the program's installation and help documents to understand how you will be using it.
  3. Backup your existing data and files and follow any CUMC requirements for storage and encryption of backups. For most faculty and staff, CUMC IT managed network drives are the easiest way to do this.
It is also important that you do not forget or lose any password you set in an encryption program. Doing so may mean that you can no longer access the files; many programs do not provide a backup method to decrypt data without the password.

Disk Encryption and Pre-Boot Authentication
Not all programs listed below can provide pre-boot authentication; it is indicated where available.

BitLocker Symantec Endpoint Encryption In the event the encrypted password is forgotten, Symantec Endpoint Encryption provides a self-service mechanism to retrieve the lost password. This feature is only available in SEE, whereas in the free products mentioned below if the password is lost, it can never be retrieved, and the encrypted information is inaccessible even to the legitimate users.

FileVault 2 Truecrypt
  • Website:
  • Use: Disk encryption software for Windows 7/Vista/XP, Mac OS X, Linux; allows for USB drive encryption as well.
    Pre-boot authentication is available for some versions of Windows, see the vendor's website for full details.
  • Cost: Free/Open Source
  • Encryption: AES-256, Serpent, Twofish
  • Password: Yes, required to decrypt partitions/volumes
  • Usage: Please see website documentation
Individual File and Folder Encryption

Secure Email Gateway
  • Website:
  • Use: File and Folder Compression software
  • Cost: Free for Columbia faculty and staff via, otherwise please see the WinZip website.
  • Encryption: Standard Zip 2.0 and AES-128 & 256 bit
    Do not rely on Zip 2.0 encryption to provide strong data security
    WinZip's implementation of the AES algorithm has been FIPS-197 certified by NIST.
  • Password: Yes, files can be password protected.
  • Usage: See the WinZip website or information on the CUIT website.
  • Website:
  • Use: Encryption of individual files (Word documents, Excel spreadsheets, etc.)
  • Cost: Included with Office
  • Encryption: AES-128/256 encryption
  • Password: Yes, files can be password protected
  • Usage: Open or create the file you would like to encrypt. Find the password protection options (Office 2013 and 2010 for Windows go to the File tab - Info - Protect Document - Encrypt with Password; Office 2011 for Mac open Tools - Protection; otherwise use the program's Help menu) and follow the prompts to set a password.

| TOP |

Last updated 4/02/2014

bullet Home                bullet Faculty and Staff                bullet Students                bullet Policies                bullet About CUMC IT
CUMC Home | At Columbia University | Affiliated with New York-Presbyterian Hospital | Comments | Text-Only Version