Endpoint & Workload Protection · EP-Q06

Question: Are removable media, external devices, and USB ports controlled to prevent data exfiltration or malware introduction?

Why This Matters

Removable media remain a major infection and data-leak channel. Policy-driven controls ensure devices are used only when necessary and under supervision.

Maturity

0 — Unaware
No controls; any device can connect.
1 — Ad Hoc
Users discouraged verbally; no enforcement.
2 — Defined
Removable-media policy issued; AV scan required.
3 — Managed
USB control enforced via GPO / MDM; exceptions logged.
4 — Integrated
DLP tools monitor transfers; alerts integrated with SOC.
5 — Optimized
Context-aware data-flow controls with adaptive risk policies.

How to Level Up

From → To Actions
0 → 1 Communicate risks and disable autorun globally.
1 → 2 Publish formal removable-media policy; enable AV scanning.
2 → 3 Deploy GPO/MDM to restrict ports; record exceptions.
3 → 4 Integrate DLP and EDR to detect data transfer anomalies.
4 → 5 Implement adaptive controls (by device type / classification).

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

Purpose Tool Notes
USB control Windows GPO / USBGuard (Linux) Native or open-source enforcement.
DLP lite MyDLP Community / OpenDLP Entry-level data-leak prevention.
Logging Wazuh / Sysmon Track device connection events.

Common Pitfalls

Compliance Mapping

Standard Clauses / Notes
ISO/IEC 27001:2022 A.8.11 Data Leak Prevention
CERT-In 2022 Section 9 (Removable Media Control)
DPDP Act 2023 Sec 8 (Data Security Safeguards)
NIST CSF 2.0 PR.DS-03 / PR.PT-04
NIRMATA Mapping EP-Q06 links to data-leak control evidence.