Saturday, February 20, 2010

US Military Lifts 15-Month Ban on Removable Media

Via govinfosecurity.com -

The military has lifted its all-out ban of removable media, but will continue to have some limits on their use, including the prohibition of non-government owned devices.

"After extensive testing of mitigation measures, DoD decided to make this technology available again on a strictly controlled basis on DoD computers," Navy Vice Admiral Carl Mauney, deputy commander of the United States Strategic Command, said Friday in an e-mail response to an inquiry about lifting the ban. "Since the order restricting use of removable media, DoD developed capabilities and processes that allow safe use of these devices. Removable media use will be limited to mission-essential operations, and only after strict compliance requirements are met."

The military issued a communications tasking order announcing the lifting of the ban last Friday within the military.

In November 2008, the military suspended the use of USB flash media and removable storage devices on all Defense Department networks, including USB thumb drives, memory sticks/cards and camera flash cards, because some Navy personnel failed to follow procedures aimed at protecting the networks from viruses and safeguarding data stored on Defense systems.

[...]

Here are the conditions the military is imposing on removable storage:

  • Employing approved procedures and hardware that prevent unauthorized use, and scan, clean and wipe the devices removing malicious software.

  • Restricting use to operational mission requirements

  • Allowing only properly inventoried, government-procured and -owned devices for use in Defense Department information systems.

  • Prohibiting personally owned devices on all military networks and computers.

  • Banning use of DoD-procured and owned devices on non-government networks or computers without authorization from an approval authority.

  • Using flash media only as a last resort to transfer data from one location to another and only when other authorized network resources are not available.

  • Subjecting randomly selected users and drives to periodic audits.

  • Requiring combatant commands, cervices, and agencies to establish their own approval authorities for determining whether selected flash media may be used within their individual organizations.

No comments:

Post a Comment