UNCLASSIFIED  5.9 Have in place effective and current contingency, recovery, investigatory and reporting procedures to enable timely response to malicious code attacks. Portable and Removable Media Security Portable and removable media devices increase workplace productivity by enabling access to corporate network resources anytime, anywhere. Therefore, the devices are a popular way of gaining access to corporate network resources. Apart from devices that organisations that organisations supply, IT departments face pressures to accept the trend of bring your own device (BYOD) where staff seeks to use personally owned devices at work. However, the portable devices expose sensitive information assets to security risks greater than one would expect in office environments usually due to the lack of physical security measures. Thus, portable and removable media security aims to achieve the outcomes below by balancing the benefits and risks of mobile devices. IS8 – All organisations using portable and removable media must adopt formal procedures to prevent the unauthorised disclosure, modification, removal or destruction of assets, and interruption to business activities. As a minimum requirement, organisations must: (a) perform a formal risk/benefit analysis before use of the media; (b) as part of a formal policy, require authorisation to use and transfer the media; (c) use baseline builds that, by default, lock down access to media drives; (d) encrypt devices to deter unauthorised access; (e) enforce security policy on media to detect and resist unauthorised use; (f) conduct user awareness training; (g) audit user actions; and, (h) prevent the holding, storage and processing of sensitive information on personal devices. To achieve the security outcomes mandated above, organisations must:  Lock down host devices to stop users changing default configurations and thereby enabling malicious actors to execute privileged commands;  Use full disk hardware encryption for devices processing sensitive data;  Ensure that users understand that maintaining physical custody of the device is the best form of defence;  Not allow the use of privately owned devices to process, store or remotely access critical infrastructure, programs and data except in emergency, shortterm situations where it is not practical to issue official equipment;  Define procedures for the timely termination of emergency use of privately owned devices to process, store or remotely access critical infrastructure;  Prevent devices that do not comply with organisational policy, such as the use of hardened configurations, from connecting to the corporate network;  Give users appropriate training in the handling of authentication credentials such as encryption keys, hardware tokens, smartcards and passwords; 30

Select target paragraph3