Disk Encryption
This option checks for the existence of disk encryption running on the endpoint device.
Disk encryption ensures that files are always stored on disk in an encrypted form. The files become available to the operating system and applications in readable form while the system is running and unlocked by a trusted user. An unauthorized user inspecting the contents of the disk directly finds garbled random-looking data instead of the actual files.
With user data encryption enabled, the /home directory in the file system is encrypted and user data is available when the system is running. The user /home partition is mounted on a separate disk partition and block level encryption is enabled for that disk.
Note: By default, the disk encryption check only detects for the presence of the disk encryption software but does not require that particular disk drives are encrypted. On a Windows platform, it is possible to require that the default C:\ drive is encrypted. For more information, see Contact Cisco Secure Access Support.