Encrypt data on end-user devices containing sensitive data. Example implementations can include:
Windows BitLocker®, Apple FileVault®, Linux® dm-crypt.
Laptops are protected by full-disk encryption.
Storing confidential information on removable media should be avoided. When removable media is used to transfer confidential information, appropriate security is used (e.g., full disk encryption with pre-boot authentication).