Checklist
Encrypted volume review checklist
Encryption slogans age poorly. A review that only asks “is it encrypted?” misses mounts that bypass the volume, keys stored beside the data, and exports that left the boundary last spring. Use this sequence when you have a quiet afternoon and a non-production target.
1. Name the object
Write the volume label, host, path, and owner in one line. If two people disagree on the name, stop and reconcile before testing controls. Misnamed surfaces create duplicate findings and false closes.
2. Confirm what encryption covers
Distinguish full-volume encryption, folder-level tools, and application-level sealing. Note any plaintext cache, search index, or thumbnail store that sits outside the cipher. Screenshot the setting that proves the mode — not a marketing page.
3. Trace key custody
Ask where unlock material lives, who can export it, and whether a laptop reboot still leaves a session unlocked. If the answer is “the vendor handles it,” record which console role can still rotate or escrow keys.
4. Check the quiet exits
Look for scheduled sync jobs, offline packs, and “temporary” share links. Encryption on the primary volume does not travel with every copy unless you verify it.
5. Write one re-runnable finding
Pick the strongest gap you found and write: evidence, interpretation, next check. Leave adjectives out. Tomorrow’s reviewer should be able to repeat your step without a call.
Want guided labs? See Vault Audit Fundamentals or the Secure Storage Review Center overview.
Educational content only. Not Financial Advice.