Overview

Security Requirements for 03.08.08 Shared Media

Requiring identifiable owners (e.g., individuals, organizations, or projects) for portable storage devices reduces the overall risk of using such technologies by allowing organizations to assign responsibility and accountability for addressing known vulnerabilities in the devices (e.g., insertion of malicious code).

Evidence

  1. 03.08.08.a

    The use of portable storage devices is prohibited when such devices have no identifiable owner