Here are some suggestions to use as a starting point for developing a portable storage device.
Here are some suggestions to use as a starting point for developing a portable storage device policy.
1. Identify who the policy applies to, including visitors.
2. Identify the technologies and devices to which the policy applies, such as CD burners, USB memory sticks and PDAs.
3. Identify approved portable storage devices and any associated products, such as data encryption software if applicable.
4. Briefly explain why portable storage device usage is a concern and how the policy is intended to help.
5. Differentiate between personal and business-owned portable storage devices, with rules such as “personal MP3 players may not be attached to company PCs or the company network” and “only company-provided and approved USB memory sticks may be used for data storage and transport.”
6. Address the physical security issue with a statement such as “staff must exercise reasonable care to protect against theft of the portable storage device which they have been issued” and “theft of the device must be reported to [insert name].”
7. Include a detailed section on data handling with statements such as “any storage or transportation of data using a company-approved device must comply with the company policy on information handling.”
8. Specify when and how portable storage usage is allowed and how it will fit with existing security, such as “the portable storage device may not be used to run or serve software when attached to the corporate network” or “before attaching a portable storage device, the user must be identified and authenticated and a virus scan completed.”
9. Use clear, assertive and unambiguous language throughout.
10. Educate all affected and responsible parties on the policy and its history (such as why MP3s don’t belong on the network).




