HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 4.131 Encryption of Lotus Notes databases

S 4.131 Encryption of Lotus Notes databases

Initiation responsibility: Head of IT Section, IT Security Management

Implementation responsibility: Administrator, users

The abstract structure of Lotus Notes databases can be presented as follows. A database contains several documents and one document consists of several document fields. The fields contain the actual data. If databases contain data with an increased protection requirement, then this can be protected using encryption. Encryption can either be applied at database level - in which case the entire contents of the database are encrypted - or, if the database contains data having different protection requirements, to individual document fields. For example, in a product database the fields containing certain cost prices could be kept encrypted. Encryption is not carried out at document level. The storage location of a database - on the server or locally on the client - will have a critical effect on the encryption possibilities.

The aspects described below must be considered for the two types of encryption.

Database encryption

Field encryption

Note. The use of "hidden paragraphs", i.e. text fields which are not displayed, is not a suitable way of protecting sensitive data. It is possible to view them, for example in the Properties dialogue of a database or with Notes Designer.

Depending on the type of information stored in a database and the related requirements of confidentiality and integrity, it might be necessary to encrypt this data. The boundary conditions should be defined here, e.g. in the security guidelines for Lotus Notes (seeS 2.207 ). The users must be informed of the functioning and protection mechanisms involved in the encryption of Lotus Notes databases.

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
last update:
July 2001
home