Laptop Donations (454A/21)


While it is welcome that you are donating unused laptops to schools – as per today’s press release – I have some concerns about data security, particularly in light of the notebook stolen from a police car last year, endangering the safety of witnesses, which I would not wish to see repeated. Could you please therefore answer the following questions:


  1. Do/did the hard disks contain(ed) data that is/was protectively marked or classified as OFFICIAL, SECRET or TOP SECRET?
  2. Are/were the hard disks encrypted, and if so, to what standard of compliance?
  3. Were the laptop hard disks removed and destroyed, and if so, to what standard of compliance? (If the hard disks remain in the laptops then…)
  4. Is a user required to enter a ‘BIOS password’ or similar pre-boot credentials before any of the laptops boot into the operating system stored on the hard disk?
  5. Have any accounts and cached credentials on the laptops been secured against brute force attack and other kinds of attack, and if so, how?
  6. Have any laptop network connections been secured against unauthorised connectivity or attack, and if so, how?
  7. Have any physical laptop connections and ports such as USB ports been secured against unauthorised attack, and if so, how?
  8. Have school IT administrators been issued with instructions as to how to repurpose the laptops securely, and if so, please can we see these instructions?


Please find attached our response.

