Jump to content

Recommended Posts

Posted

Hey

 

I have told my SMT team that i will be blocking all use of usb sticks to stop staff bring in any king of virus and to stop them using unencrypted stick, they have asked me if any other schools have this policy

 

feedback would be welcome.

 

Thanks

Posted (edited)

It's been talked about but no school yet I've dealt with has implemented such a program - it's too much aggravation. However e.g. for the cost of a 64GB memory stick per staff member, we can't duplicate that storage space on our servers at that price point, have redundancy and backup of it. We simply can't afford it.

 

We do use hardware encrypted USB sticks however where needed, everything else is in the cloud with OneDrive or on file servers etc.

Edited by DrBeaker
Posted
Our policy is to block all "unapproved" USB sticks/disks, which we manage via Netsupport DNA and Bitlocker. Anyone wanting to use a USB device must bring it to us for encryption and after that, we allow it for use.
Posted

a) block executing code from where users can write to, ie use SRP/AppLocker to whitelist only c:\program files, (x86), and windows.

b) GPO to only allow writing to bitlocker encrypted drives

c) Massive signs saying "We can't reset your usb drive password, if you forget it, you've lost your data"

Posted
We only allow USB devices which we've approved via group policy. By default they won't work until we add them to GPO. All USB media devices will need encrypting with bitlocker to work. We initially wanted to block all USB devices but found there are certain subjects that use USB devices for certain things like coding and engineering.
Posted

I have seen USB stick blocking done, but it was a real headache.

 

We've taken the middle approach of saying the using USB sticks is discouraged, please use the corporate Google Drive. If they must use a USB stick, we force encryption before you can write any school data and take it off site.

 

We took it more as a data protection issue, rather than an antivirus issue.

Posted
We only allow USB devices which we've approved via group policy. By default they won't work until we add them to GPO. All USB media devices will need encrypting with bitlocker to work. We initially wanted to block all USB devices but found there are certain subjects that use USB devices for certain things like coding and engineering.

 

Wait.. You can do that?

Do you have a guide? One of the main thing that's stopping us blocking USB devices is Photography. If we could somehow whitelist the cameras that'd be great.

Posted
We block them for students, staff can use encrypted sticks that we have given out

 

School where I'm a governor block them. A school I worked at blocked them after a data breach. As a G Suite school it wasn't such a big deal. They enabled copiers to scan to drive, that was necessary to overcome some grumbles.

Posted

We do the same as @mavhc. Not too worried about the safety of things being brought in on USB, so we allow all users to read data from USB. This supports about 99.9% of all use cases but keeps things tight in terms of data protection. Data can only be written to USB if it's BitLockered.

 

We offer to set up BitLocker on staff-owned USB devices and store a copy of the BitLocker recovery key for them, but only a handful have taken us up on the offer. The majority were wanting to use the devices still in home computers that don't support it.

 

Allowing unencrypted devices as read-only will head off the vast majority of grumbles, so you might want to consider introducing that as a first stage. We found that people think they need to write stuff to USB far more than they actually do.

Posted (edited)
Wait.. You can do that?

Do you have a guide? One of the main thing that's stopping us blocking USB devices is Photography. If we could somehow whitelist the cameras that'd be great.

I don't have a guide but must be able to find something on the internet. It's just a simple GPO change: Computer Configuration > Policies > Administrative Templates > System > Device Isntallation > Device Installation Restrictions > Allow installation of devices that match any of these device IDs.

 

You can create a list of Device IDs that you would like to allow. To get the device ID: https://support.shippingeasy.com/hc/en-us/articles/203086919-How-to-Find-the-Vendor-ID-VID-and-Product-ID-PID-for-my-USB-scale-Applet-Integration-

Edited by RLR
  • Thanks 1
Posted

We currently still allow them for Staff only, but have in the AUP that they should not be used for confidential information. I want to take this further (ideally block them) but I think allowing access to bitlocker encrypted devices only is the best compromise

 

For those of you who configured this bitlocker restriction, did you use group policies or a third party tool?

Posted
Biggest problem we have is non-staff people (people delivering training, external agencies etc..) assuming they can just come and plug a stick in.
  • Thanks 1
Posted

If you do choose to force Bitlocker encryption make sure users are told to backup their USB data first before encrypting (or only allow IT to encrypt).

 

We have encountered several Bitlocker encryption failures on faulty or partially faulty USB drives making the drives unusable. Recovering data from a damaged Bitlockered drive is not nice and sometimes, in our experience, not possible.

Posted
Biggest problem we have is non-staff people (people delivering training, external agencies etc..) assuming they can just come and plug a stick in.

 

TBH this was one of the main reasons for us allowing vanilla USB storage as read-only. It means that guests, interview candidates, etc. can still deliver presentations, etc. without anyone needing an IT tech.

 

The biggest issue we've encountered with our approach is when it comes to managing the contents of memory cards from cameras and dictaphones. Staff would previously have mounted the card on their laptop and renamed/reorganised/deleted the contents that way. Now they're limited to using the device's own controls, which is less convenient for them.

  • Thanks 1
Posted
Biggest problem we have is non-staff people (people delivering training, external agencies etc..) assuming they can just come and plug a stick in.

 

We tend to tell staff that anyone doing a presentation will be given a guest login. Anything they want to bring in should be handed to IT to copy over to the guest login's Documents folder (after scanning it) so they can access it.

 

This works OK, apart from the times they just roll up without warning.

Posted

USB storage is read only here and executables are blocked. We've been like this a couple of years now. This way users can create stuff elsewhere and bring it in to use, but can't export data to USB. We do this through Netsupport DNA, but the same could be achieved using Sophos. It also allows users to download pictures from cameras etc. without us having to get involved.

 

All our users have a GSuite account with unlimited storage.

 

There are of cause a very limited number of devices which we have approved to have data written to them - but using DNA we are also able to limit where in the building these will function.

Posted
We Block righting to USB and only allow read access. We would love to block all USB storage devices but as we cant white list cameras we still need the read access.
Posted

We did this recently but could only half enforce is because of issues with students needing access to SD cards etc. for Media and Photography.

 

We allow read-only access to prevent users transferring mass data on to external storage devices before they leave.

 

We also enforce AppLocker which does a fantastic job of preventing anything running which isn't in program files or a set of specific folder locations.

Posted
Microbits are the worst, have to write to those to work, unless you use serial port.

 

Yep, we have these. This is why we have a 2 Group policy settings for USB devices. One for teaching machines and one for Admin machines. For teaching machines, we only allow certain USBs devices based on their ID.

Posted
Hey

 

I have told my SMT team that i will be blocking all use of usb sticks to stop staff bring in any king of virus and to stop them using unencrypted stick, they have asked me if any other schools have this policy

 

feedback would be welcome.

 

Thanks

 

What anti-virus software do you use out of interest. It might be worth checking to see if there is an option to block USBs via the anti-virus. We use Sophos Anti-Virus and we can block USBs via the Sophos Central console.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...