GRC Careers

HomeResourcesBitLocker

CS-079 · Endpoint Security

BitLocker

Full-disk encryption for Windows that protects data when a device is lost or stolen.

Executive Summary

BitLocker is the full-disk encryption feature built into supported editions of Microsoft Windows. It protects the data on a drive so that a lost or stolen device does not expose its contents. On most modern PCs it works with a Trusted Platform Module to bind encryption to the device and unlock the disk only when the system boots in a trusted state.

What It Is

BitLocker is Windows disk encryption that scrambles the contents of a drive and only makes them readable when the correct key is supplied. It typically uses the Trusted Platform Module, a secure chip that stores the encryption key and releases it only when the boot process is unchanged, so the disk unlocks automatically for the legitimate user but stays locked if the drive is removed or the boot chain is tampered with. Organizations can require an additional startup PIN or a USB startup key for higher assurance, and a recovery key exists as a backup way to unlock the drive. BitLocker To Go extends the same protection to removable drives.

Why It Matters

Laptops and portable drives are lost and stolen constantly, and without encryption anyone who has the physical device can read its files by moving the drive to another machine. Full-disk encryption turns a lost laptop from a reportable data breach into a lost piece of hardware. Many regulations and contractual obligations expect encryption of data at rest on mobile devices, so BitLocker is often a compliance requirement as well as a practical safeguard. For professionals, deploying and managing disk encryption is a routine endpoint security task.

How It Works

BitLocker encrypts the drive with a key that is itself protected by one or more unlock methods. In the common configuration the Trusted Platform Module measures the boot components and releases the key only if they match a trusted state, so the disk decrypts transparently when Windows starts normally. If the drive is moved to another computer, the boot state changes, or someone tampers with the startup process, the TPM withholds the key and the system falls back to requiring the recovery key. Administrators can strengthen this by adding a startup PIN so the user must supply something they know. The recovery key is a long numeric backup credential that should be stored, or escrowed, in a central directory or management service so it is available when a device needs it and is not left on the device itself.

Architecture Diagram

Device powers onTPM measures the boot stateTrusted state releases the key and disk decryptsChanged or tampered state requires the recovery keyRecovery key escrowed centrally for backup
On a normal boot the TPM releases the key and the disk decrypts; a changed state forces recovery-key entry.

Visual Workflow

Confirm devices have a Trusted Platform Module and a supported Windows edition.Define an encryption policy, including whether a startup PIN is required.Enable BitLocker through device management or Group Policy across the fleet.Escrow every recovery key to a central directory or management service.Verify encryption status and recovery-key backup on each device.Monitor for devices that are unencrypted or missing an escrowed key.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

BitLocker Drive Encryption
Built-in Windows full-disk encryption for fixed and system drives
BitLocker To Go
Encrypts removable USB drives so lost media stays protected
Group Policy and device management
Enforces encryption policy and escrows recovery keys at scale
Trusted Platform Module (TPM)
Secure chip that binds the key to a trusted boot state

Industry Standards

NIST SP 800-111
Guidance on storage encryption for data at rest on end user devices
FIPS 140 validated cryptography
Standard for validated cryptographic modules used by encryption
CIS Microsoft Windows Benchmarks
Includes recommended BitLocker configuration settings

Career Relevance

BitLocker deployment and key management are routine for endpoint security engineers, IT security administrators, and desktop engineering teams, and they appear in SOC and incident work when devices are lost. Security engineers and GRC auditors verify encryption of data at rest against policy and regulation, part of the audience AI-Governance-Jobs.com serves.

Interview Questions

Related Certifications

CompTIA Security+ Microsoft Certified: Endpoint Administrator Associate GIAC Certified Windows Security Administrator (GCWN)

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

Does BitLocker slow down a computer?

On modern hardware the performance impact is small because encryption is handled efficiently and largely in the background. For most business laptops the protection far outweighs the minor overhead.

What happens if a user forgets their PIN or the device changes state?

The system falls back to requiring the recovery key. This is why organizations escrow recovery keys centrally, so the help desk can supply the key after verifying the user's identity.

Does BitLocker protect a laptop that is stolen while turned on and logged in?

No. Full-disk encryption protects data at rest when the device is off or the drive is removed. A running, unlocked device is not protected by encryption, so strong sign-in, screen locks, and requiring re-authentication after sleep still matter.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

CompTIA Security+Microsoft Certified: Endpoint Administrator AssociateGIAC Certified Windows Security Administrator (GCWN)

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: BitLocker
  3. Go deeper: FileVault
  4. Go deeper: Windows Security
  5. Validate it: work toward CompTIA Security+
  6. Find the role: browse current openings

Related sheets

More in Endpoint Security

Share this LinkedIn Facebook X Email