Skip to content
arrow_back
search
ISM-1359 policy ASD Information Security Manual (ISM)

Establish and Maintain Removable Media Policy

Organisations must create and uphold a policy for using removable media safely.

record_voice_over

Plain language

Having a policy for using removable media, like USB sticks and external hard drives, helps keep your organisation's data safe. Without clear rules, staff might accidentally introduce viruses or lose important information, which could harm your business and break privacy laws.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A removable media usage policy is developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-1359
priority_high

Why it matters

No removable media policy increases the chance of malware via USBs and uncontrolled copying of sensitive data off-network.

settings

Operational notes

Maintain a removable media policy covering approved devices, encryption, scanning, labelling, secure storage, and disposal; review at least annually.

Mapping detail

Mapping

Direction

Controls