Answer yes if your organisation subjects the use of removable media to technical controls (these can include DLP solutions, encrypted USB drives, training and awareness etc.). If yes, please describe the nature of these controls within the notes.
What is it?
Where the use of removable media is required, additional controls can be applied to limit how and when they are used, or what types of data they are used for.
The compensating controls you wish to apply will depend on your business environment and individual use-cases for removable media. Controls might include:
These measures all help ensure data is not accidentally or maliciously put on removable media and exfiltrated from the organisation when technical controls to prevent all use of removable media are not available or sufficient.
Why should I have it?
If you are not able to prevent the use of removable media entirely, compensating controls help reduce the risk of data loss through such media for yourself and clients that entrust you as a supplier of services.
Which controls are useful and appropriate will depend on your specific business context and, in some cases, local employment and privacy laws. We strongly recommend you prevent the use of removable media where possible to minimise the need for compensating controls.
You should ensure any controls are documented and agreed to by all necessary parties.
There are numerous consultancies or individual consultants that will be able to assist in crafting a policy and control set that meets your business and technical requirements.
If you would like to contribute to this article or provide feedback, please email knowledge@riskledger.com. Contributors will be recognised on our contributors page.