The usage restriction of portable storage devices shall be ensured through an appropriate
documented policy and supporting safeguards.
Portable storage devices containing system data shall be controlled and protected while in
transit and in storage.
Guidance
Protection and control should include the scanning of all portable storage devices for malicious code
before they are used on organization's systems.
The organization should technically prohibit the connection of removable media unless
strictly necessary; in other instances, the execution of autoruns from such media should be
disabled.
Removable media includes e.g. flash memories, SD memories, removable storage drives, USB sticks and DVDs.
The organization has defined which removable media is allowed to be used.
Storing confidential information on removable media should be avoided. When removable media is used to transfer confidential information, appropriate security is used (e.g., full disk encryption with pre-boot authentication).
When removable media is an important part of an organisation's operations, more specific rules have been defined for securing removable media and the information they contain.