From the little bit I've been able to gleen from different sources, the use of an external hard drive for this kind of storage is completely contrary to current IT policies which is why all of the other questions (such as why wasn't it encrypted) are moot. The information should never have been put on the external drive in the first place so policies for securing / encrypting the data didn't exist.
The real question that needs to be answered is why the information needed to be put on a HDD in the first place.... was the employee taking work home with him/her? That kind of information would have been accessable on the network and normally stored on their network servers. It's not like it was put on the HDD to migrate it over to a new workplace PC.
__________________ EVGA X58 3X SLI / i7 980X / 3X 4G Mushkin Blackline Frostbite / XFX Pro 1000W / EVGA GTX 680 SC+ 2GB / Corsair F120 / WD 6401AALS / TT Lvl 10 GT Swiftech MCP655 WC Pump / EK XT 240 Rad / 2X Scythe Ultra Kaze / EK Supreme HF / Primochill Myriad Dual Bay Res / Dell UltraSharp U2412M Sabertooth 990FX / PhII X4 965 / 2X4G Corsair XMS3 / EVGA GTX580 + EK Block / Corsair 120G Force GT Corsair TX750 / XSPC EX240 / Swiftech MCP655-B / XSPC Dual Bay Res / ? CPU block / Bitfenix Ghost / Samsung 931BF |