Don't overlook the security risks posed by portable storage devices.
Sue is an industrial spy who has arranged to attend a meeting at the company she is targeting. She slips away from the meeting to check out the marketing department. It’s lunchtime, and the place is almost empty. Sue quickly spots a PC that’s still logged on to the network. She steps into the cubicle where she is hidden from view, plugs her 512M-byte USB memory stick into the workstation and copies several folders and a client database from the local and network drives. She unplugs and pockets the memory stick and nonchalantly leaves. The whole process takes less than 5 minutes, and nobody knows that she has stolen more than 200M bytes of corporate data.
This all too possible scenario illustrates a growing security concern. The fear is that people will use USB memory sticks, MP3 players and the like to upload malware, steal data from corporate networks, and share stolen software, MP3 or AVI files. In its report, “How to Tackle the Threat from Portable Storage Devices,” Gartner suggested that organizations forbid attachment of privately owned portable storage devices to corporate PCs. The report also recommended that desktop PCs be carefully configured to remove or disable drivers needed to use such unauthorized devices.
Certainly these risks aren’t new. People were known to steal or mishandle data or introduce viruses with floppy disks and efforts to ban floppies failed. However, in addition to floppies, administrators now have to contend with CDs, DVDs, cell phones and digital cameras with memory, MP3 players with built-in hard drives, portable hard drives and USB memory sticks. Most of these devices attach to a workstation through a USB or FireWire port, are relatively inexpensive and easy to use, and offer high-speed transfer and high-capacity storage.
What has really changed is the scope of the problem. Individuals now can copy and transport very large volumes of data in a short time. This exposes companies to a greater potential effect than anything experienced with floppies.
What can be done about this? To start, any attempt to simply ban all or even just personally owned portable storage devices from the workplace is impractical and probably unenforceable. Instead, supplement security controls with a strong and clearly worded policy to tell people what devices are allowed and how they can and can’t be used.
As a rule, such focused policies work best when supported by broader policies on network security and information handling. In particular, a supporting policy on information classification and usage would be needed to help define what information is or is not transportable, and by whom.
It also would be important to explain and market any portable storage device policy to network users (including visitors) and the administrative staff and management responsible for enforcement.
Ultimately, any portable storage device policy will need to be backed up with compliance or monitoring tools. This likely will require third-party software because standard operating system tools such as Windows 2000 Group Policy do not enable monitoring or blocking of individual ports.
There are other options, such as editing the registry of each PC. However, these labor-intensive solutions are not practical for most shops.
One product that might fit the bill is SmartLine’s DeviceLock, which lets network administrators control user access to I/O ports and storage devices on local workstations. With DeviceLock, individual users are assigned privileges depending on who they are, what device is involved, and the date and time. For example, a network administrator could let one consultant use his USB memory stick but block all other consultants from doing so. The consultant also could be blocked from attaching his MP3 player.
In the end, policy and enforcement are more likely to be effective than a ban of portable storage devices. After all, a ban isn’t going to block someone like Sue, anyway.
McKinley is a CISSP and president of Summit Communications, a network and security consulting firm. He can be reached at strategist@summit-com.com.




