a) if no longer required, the contents of any re-usable media that are to be removed
from the organization should be made unrecoverable;
b) where necessary and practical, authorization should be required for media removed
from the organization and a record of such removals should be kept in order to
maintain an audit trail;
c) all media should be stored in a safe, secure environment, in accordance with
manufacturers’ specifications;
d) if data confidentiality or integrity are important considerations, cryptographic
techniques should be used to protect data on removable media;
e) to mitigate the risk of media degrading while stored data are still needed, the data
should be transferred to fresh media before becoming unreadable;
f) multiple copies of valuable data should be stored on separate media to further
reduce the risk of coincidental data damage or loss;
g) registration of removable media should be considered to limit the opportunity for
data loss;
h) removable media drives should only be enabled if there is a business reason for
doing so;
i) where there is a need to use removable media the transfer of information to such
media should be monitored;
j) Procedures and authorization levels should be documented.
(NL ISO/IEC, 2015)
Lebanese National Security Policy Guidelines v1.7
Page
42 |