Tuesday – Cyber Tip: Removable Media Policy

Topic: Removable Media Policy
Title: Removable Media Policy: What is a removable media policy, and how can it help an organization?
A Removable Media Policy is an information security policy that outlines the acceptable use of portable storage devices such as: USB flash drives, external hard drives, memory cards, CDs, and DVDs. These devices are often used for transferring or storing data, and they can pose significant cybersecurity risks if not handled properly. Ideally, they help organizations control, monitor, and secure removable media devices, reducing security risks with their use.
  1. Scan for Malware: Always scan removable media for malware before using it on your system. Malware can spread through these devices.
  2. Limit Use: Use removable media only when necessary. Rely on more secure methods of data transfer and storage whenever possible.
  3. Physical Security: Keep removable media devices in a secure location when not in use. Avoid leaving them unattended in public places.
  4. Encryption and Data Protection:
    1. Require encryption for data stored on removable media.
    2. Encourage the use of hardware-encrypted drives.
    3. Educate users on the importance of safeguarding sensitive information.
     
  5. Access Control: Restrict access to removable media to authorized personnel only. Implement policies to control who can use these devices and for what purposes.
  6. Avoid Auto-Run: Disable the auto-run feature on your computer to prevent automatic execution of potentially harmful software from removable media.
Video Link: Removable Media
Furthermore, kindly read and ensure compliance as it relates to CITO policies regarding removable media: Removable Media Document