UNCLASSIFIED
5.9
Have in place effective and current contingency, recovery, investigatory and
reporting procedures to enable timely response to malicious code attacks.
Portable and Removable Media Security
Portable and removable media devices increase workplace productivity by
enabling access to corporate network resources anytime, anywhere. Therefore,
the devices are a popular way of gaining access to corporate network resources.
Apart from devices that organisations that organisations supply, IT departments
face pressures to accept the trend of bring your own device (BYOD) where staff
seeks to use personally owned devices at work. However, the portable devices
expose sensitive information assets to security risks greater than one would
expect in office environments usually due to the lack of physical security
measures. Thus, portable and removable media security aims to achieve the
outcomes below by balancing the benefits and risks of mobile devices.
IS8 – All organisations using portable and removable media must adopt formal
procedures to prevent the unauthorised disclosure, modification, removal or
destruction of assets, and interruption to business activities. As a minimum
requirement, organisations must: (a) perform a formal risk/benefit analysis
before use of the media; (b) as part of a formal policy, require authorisation to
use and transfer the media; (c) use baseline builds that, by default, lock down
access to media drives; (d) encrypt devices to deter unauthorised access; (e)
enforce security policy on media to detect and resist unauthorised use; (f)
conduct user awareness training; (g) audit user actions; and, (h) prevent the
holding, storage and processing of sensitive information on personal devices.
To achieve the security outcomes mandated above, organisations must:
Lock down host devices to stop users changing default configurations and
thereby enabling malicious actors to execute privileged commands;
Use full disk hardware encryption for devices processing sensitive data;
Ensure that users understand that maintaining physical custody of the device
is the best form of defence;
Not allow the use of privately owned devices to process, store or remotely
access critical infrastructure, programs and data except in emergency, shortterm situations where it is not practical to issue official equipment;
Define procedures for the timely termination of emergency use of privately
owned devices to process, store or remotely access critical infrastructure;
Prevent devices that do not comply with organisational policy, such as the
use of hardened configurations, from connecting to the corporate network;
Give users appropriate training in the handling of authentication credentials
such as encryption keys, hardware tokens, smartcards and passwords;
30