Re: disable usb devices



Will you then also work to disable the following:

* FireWire ports
* Writable CD/DVD drives
* PCMCIA/CardBus slots
* SD Card/Memory Stick/etc. slots
* Internet access (Hotmail, Gmail, Yahoo Mail, FolderShare, and so on)
* Printers and photocopiers
* Digital cameras
* Telephones

You see, there are many ways people can export data from your organization. You're looking at only one mechanism.

For most of the history of computer security, we defenders have been struggling to keep the bad guys out. Well, we've reached that point -- with modern operating systems and properly-written applications, the bad guys indeed are mostly kept out.

Now, for various reasons, we've had to turn our attention to a completely different kind of task -- applying more controls over what authorized users can do with data they're allowed to see. Think about this for a moment! It's a completely different task, one that requires new thinking, new processes, and new technologies.

You can't use old-style bad-guy-prevention methods anymore. Attempting to limit "containers" (be it the network or a PC or a memory module) has limited utility here. Instead, we must adopt new methods that allow data sources to protect themselves. Essentially, the notion of portable access control, where the object -- in this case, a file -- controls its own access and enforces its own policies, rather than relying on the container -- a file share.

Yes, this is rights management. IMHO, it's the only way we can truly start to mitigate the "authorized user threat" (I hate that term, but so far haven't come up with anything better). Implementing such a system -- say, Windows RMS -- requires a fundamental shift in thinking about the roles and work of information security. But I don't see any other way. Blocking USB drives just won't cut it: you'll simply create what I call a "circumvention vulnerability," something that encourages users to look for ways to get around the security policy. And I promise you, they'll find many.

--
Steve Riley
steve.riley@xxxxxxxxxxxxx
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com



"yepiknowiam" <yepiknowiam@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:376C801A-FB6D-411C-BC6E-A1C3044573FF@xxxxxxxxxxxxxxxx
Trying to prevent users downloading possibly sensitive files/information and
bringing it home to work on. They could easily lose a thumb drive and we are
a financial institution. It's a preventive measure. I believe there are
many risks with usb devices.

"Steve Riley [MSFT]" wrote:

Every time I see this, I have to ask: why do you want to do this? What
security threats are you trying to mitigate by disabling USB storage
devices?


.



Relevant Pages

  • Re: Need help with securing a local workstation
    ... I suggest you also change the ntfs permissions ... setting as disabling the command prompt for instance can cause batch files ... components/Windows Explorer to hide and disable drives, ... Depending on your security ...
    (microsoft.public.win2000.group_policy)
  • Re: USB flash drive not recognized
    ... Thank you for contacting SanDisk Technical Support. ... For general troubleshooting of u3 drives, ... Next we would want to try disabling all of your items on "Start-Up". ... Start-Up items are pieces of software that run automatically whenever ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: More on caching and logging
    ... or do you think it also includes corporate security ... Refusing to boot up is a felony. ... I was going to run down some process involving hard drives ... Apple did to implement this new product or will they allow it to be ...
    (comp.sys.mac.system)
  • Re: STOP 0x0000007E Error on installing Service Pack 2
    ... > ATI All In Wonder 9800 Graphics Card ... > 4) Disabling services that were not started up in Safe ... > Soundblaster and SATA drives. ... > Error Message at Startup Win XP ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: RAID 5 drive replacement schedule
    ... I checked the RAID array and found ... Raid 5 is an IT field & technologie, and adds to the security by making 1 ... failed drive NOT impact availability. ... Change drive A and hope drives B & C will last longer. ...
    (Security-Basics)