Introduction to Full Disk Encryption (FDE)

Full disk encryption (FDE) is a security safeguard that protects all data stored on a hard drive from unauthorized access using disk-level encryption. With FDE, all data is encrypted by default, taking the security decision out of the hands of the user. The most common use case for implementing FDE is to protect data loss due to lost or stolen laptops, which is often sufficient enough to avoid costly data breach notification requirements.

The purpose of this guide is to provide worthwhile strategies for implementing full disk encryption throughout your organization, and to identify common pitfalls to avoid. The following topics are covered on this page:

Define the Scope

Top of page

Develop Policies and Procedures

Top of page

Choosing Software, Hardware, and Configuration

Top of page

Implementation and Support

Top of page

Understand the Limitations

Top of page

Dos and Don'ts

#Top of page

Additional Resources in the Guide

Top of page


(question) Questions or comments? (info) Contact us.

(warning) Except where otherwise noted, this work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License (CC BY-NC-SA 4.0).