HomeControl Library › 3.8.8
3.8 Media Protection3 ptsPOA&M-eligible

3.8.8 — Ban ownerless USB drives

Prohibit the use of portable storage devices when such devices have no identifiable owner.

No using portable storage that has no identifiable owner.

What it actually means

Prohibit the use of portable storage devices when they have no identifiable owner — no plugging in 'found' or unknown USB drives, a classic malware vector. Set the policy and, ideally, enforce it with endpoint controls that block unknown removable devices.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library