When it comes to managing USB storage devices on your network, what solutions do some of you have in place? We need to manage this better for CMMC (compliance).

915 viewscircle icon3 Comments
Sort by:
Analyst, Corporate Development10 months ago

I agree with James Coe below - your wider information security must deal with enterprise risks systemic to your organisation.
Management of USB data sticks must align to your business objectives and Data Loss Prevention information security policy.
Some users may need USB data sticks - but generally these need to be managed carefully in alignment with the information security polices but exception only, with request made on the ITSM for auditing and recorded in the risk register.

Generally USB data-sticks must not be allowed but USB power delivery is - with enterprise endpoint tools like MS-intune.

Mitigations and countermeasures need to be put in place to allow data-sharing between employees and pre-screened partners.

Identity and Access Management (SSO, MFA etc) with a cloud secure share (google workspace or MIcrosoft Team/sharepoint) is your an enterprise alternative and with manageable data collaboration tools.

Enterprise Systems Architect in Government10 months ago

Managing USB storage should be one part of a broader information security strategy. On a Microsoft-driven stack starting points are BitLocker, Intune, Microsoft Purview Information Protection, Microsoft Purview Data Loss Prevention.

Here's how you can enforce encryption for Windows computers and removable storage with Intune:

https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-protection-windows-10#windows-encryption

It's also possible to do so via Windows Group Policy Objects:

https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/configure?tabs=common

IT Manager in Telecommunication10 months ago

You can use device control of some endpoint protection solutions, like Kaspersky, but I use Sophos Intercept X because you don´t only can block USB ports, it also has a strong integrated DLP solution in the same product to prevent leaks by email, Google Drive, WhatsApp etc.

Content you might like

Yes, it is part of my vision and mission 39%

Yes but I have difficulty to enroll in 43%

I know them but I don't believe they are a must be32%

Our business is focused on the ROI, period.9%

I am not sure, let's discuss in the comments.

View Results