Skip to content
arrow_back
search
ISM-0343 policy ASD Information Security Manual (ISM)

Disabling Unnecessary Access to Removable Media

Disable writing to removable media unless it's necessary for business.

record_voice_over

Plain language

This control is about stopping people from saving data onto USB sticks and other removable drives unless it's needed for work. It's important because if this isn't controlled, sensitive information could easily fall into the wrong hands if the device is lost or stolen.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

If there is no business requirement for writing to removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.
policy ASD Information Security Manual (ISM) ISM-0343
priority_high

Why it matters

Allowing write access to removable media enables data exfiltration and malware transfer via USB devices, risking disclosure of sensitive information.

settings

Operational notes

Use device access control to block removable media write access (allow read/approved devices only) or disable USB storage interfaces, and review exceptions regularly.

Mapping detail

Mapping

Direction

Controls