Jump to content

Recommended Posts

Posted

Hello,

Could I ask if anyone has tackled a removable media ban/policy? We've had an audit report which recommends banning removable media in its entirety but this leaves several conundrums

 

* What to do with staff/learners who do not have internet access at home

* How to manage those working with large files that are not suitable for cloud sync such as media 4k videos

 

This then complicates things as if you don't ban them but fall back to a "require encryption" model how does that work in a Windows AND Mac environment in terms of technical control. I've looked at solutions such as cocosys but very expensive. If it was just Windows we could apply a group policy requiring bit locker.

 

Thoughts most welcome!!

 

Rob

Posted

We have it banned as a school policy. Banning it completely with technology is somewhat complex as there are always going to be edge cases - cameras in media is one. Some older devices also need them - AV stuff in the hall uses them.

 

What has worked well for us is making sure there is an easy + reliable alternative. Google drive and drive file stream have been much easier for staff to use. They don't have to worry about forgetting it, losing it, breaking it, plus they can work collaboratively without versioning hell when sharing, and if something gets deleted or overwritten, its just a mater of going in the version history. They can even moan at the person who did it. There's always a few users though that insist on the old way, however once most staff saw the benefits of using it they moved without too much fuss. If they desperately want office, then they can use file stream and its the same as a memory stick or network drive.

 

We also limit our support - We would help copying stuff up to google, setting up encrypted devices etc, but we would be reluctant to support broken devices. We used to get lots of broken memory sticks with the only copy of work.

 

The policy obviously needs to be backed by SLT and line managers.

 

These days staff need to be getting up to speed on security and backups. We can't hand hold all the time.

 

We do have a 1Gb internet connection, but uploading videos works reasonably well. Google drive uses similar technology to youtube, so playback can be scaled as appropriate. When we first moved, we used RClone to do big uploads for some staff. We had local network drives full of videos, so once staff had organised what was there, we could just leave it running overnight from a Server or PC with USB 3 if it was a portable drive. I'd say there isn't much difference in speed between google drive and usb storage. If anything google is probably faster. At a minimum, we expect staff + students to put a copy on their google drive, even if they work on it locally. They don't get much sympathy if they haven't backed it up.

Posted

Going back to when encrypting USB sticks came about we used to let anyone open stuff on drives but not write to them, this was long before the likes of Drive and OneDrive etc.

 

The only thing I can see is that students if there they have no internet at home as such you would be stuck but for everyone else there is no excuse to upload or even email document to yourself.

 

Tough call, risk assess it and decide what is best for the organisation, just because it says something in an audit its a recommendation, put measures in place even if its to make them read only or only allow a small group of people to write to them or for those that need them supply some form of encrypted one.

Posted

Limit to read-only and prevent execution. That's for data protection and security, respectively. Arguably better to not allow people to BitLocker their own stuff, either.

 

That allows for downloading from cameras, etc. without causing too much of a jolt for people. Having something like Drive File Stream on hand will help keep things on an upward trajectory, too.

  • Thanks 1
Posted
Limit to read-only and prevent execution. That's for data protection and security, respectively. Arguably better to not allow people to BitLocker their own stuff, either.

 

That allows for downloading from cameras, etc. without causing too much of a jolt for people. Having something like Drive File Stream on hand will help keep things on an upward trajectory, too.

 

Hi,

 

We currently allow staff to use any USB device but want to make sure these are encrypted now. I can see the option to deny write access through Group Policy but how can you prevent execution?

 

Also, just checking - is there definitely no way through Group Policy to disallow access to a USB that isn't Bitlockered?

 

Many Thanks

Posted

I think Applocker is what you are after for blocking execution.

 

You can probably be quite strict with what you block, and then just add exclusions for the odd things that you have checked and approved.

 

If you use drive filestream, you probably want to block execution on that as well.

  • Thanks 1
Posted

Current school has encrypted laptops for all staff who need to work from home, plus OneDrive and G Drive, and policy saying not to use removeable disks. Cameras etc are permitted. Of course, you could save a sensitive Word doc on a camera then take it home, but users will find a way round all security if their need is great enough and/or if your restrictions are too inhibiting.

 

Any students without Internet access have been given a 4G hotspot.

 

Re the Windows and Mac question, we addressed that at a previous school with the USB sticks which you unlock first with PIN or biometrics, then have 10 seconds to plug in to a computer. We had policy in place saying any sensitive information must be encrypted on removeable media, but didn't force this because of cameras, etc.

Posted

AppLocker or SRP to prevent execution. That's getting into a separate thing really, but best practice for those is to have them set up as an allow list (i.e. block everything by default but allow only from certain locations... C:\Windows, C:\Program Files, etc. Locations). If you have allow list AppLocker/SRP in place, you don't need to 'do' anything further to prevent execution from removable media, since it'll be the case by default. You'll never really catch them all, otherwise.

 

N.B. The more common terminology will be whitelist vs blacklist, but I'm feeling a bit woke today.

 

As for preventing even read-only access to non-BitLockered media, I think you might be out of luck on the Group Policy front.

  • Thanks 1
Posted

We moved from a straight ban to making removable media, read only and preventing execution.

 

This resolved 99% of all the issues, we still have a process for allowing writing to USB when required but this is generally Exam work for the boards and staff leaving and wanting to take "their" materials with them, which has a special process with the DPO and myself to ensure it is their materials and not just a hoovering of data and copyrighted materials.

Posted

We looked at a complete ban using GPO, but couldn't make it work for us due to the need to be able to connect cameras and SD cards from cameras and Lego devices. You can create an allow list by hardware id, but you need to create a policy for every type of device you have (i.e. every model of SD card etc). We couldn't use GPO to enforce bitlocker for the same reason.

 

We did it by organisational policy. We'd had a near miss - a SenCo mislaid a stick with all manner of personal details on it. Much panic and many tears later it turned up in a different handbag. That caused enough concern that people stopped using them for confidential data, but I suspect that organisational memory will lapse as staff have moved on and it will become a problem again.

 

I think I was the biggest user of memory sticks... I would find it very inconvenient not to have a stick with drivers and scripts and BIOS updates on it. But I am different to ordinary staff [emoji57]

Posted
I think I was the biggest user of memory sticks... I would find it very inconvenient not to have a stick with drivers and scripts and BIOS updates on it. But I am different to ordinary staff [emoji57]

 

None of which would matter if they got lost, of course. Which is why at my previous school we didn't ban USB, but instead had policy about what to store on them. That seemed to work, and also reinforces the message about the human responsibility - you can't enforce what paper people take off-site, so why enforce what Word docs they can take? Instead, have a policy which covers both.

  • Thanks 1
Posted
We've banned students from using removable USB devices and we have a BitLocker policy that requires staff to encrypt a removable drive before being able to put data on it.
Posted

Just remember that the advice to ban is part of risk treatment. It is not to be taken out of context and there can be other treatments that you can do to get a similar result.

You’ve already been told some of the alternatives. Propose them and see what you get back.

Posted
We've banned students from using removable USB devices and we have a BitLocker policy that requires staff to encrypt a removable drive before being able to put data on it.

 

Do you or does anyone else know what happens if a user plugs another already encrypted drive in such as a Data Traveller? I presume it just won't work because it's not Bitlockered?

 

Don't have one to test and would be good to know.

 

Many Thanks!

Posted
Do you or does anyone else know what happens if a user plugs another already encrypted drive in such as a Data Traveller?

 

Don't those require you to run a .exe from the USB drive to decrypt the partition on it? I very much hope you've got that blocked...

  • Thanks 1
Posted
Do you or does anyone else know what happens if a user plugs another already encrypted drive in such as a Data Traveller? I presume it just won't work because it's not Bitlockered?

 

Don't have one to test and would be good to know.

 

Many Thanks!

It will prompt you to encrypt it anyway, so you'd effectively have a double-encrypted device. I encountered this with hardware-encrypted USB devices, which then had to be encrypted again with BitLocker, so the user had to put in two passwords to access the data.

  • Thanks 1
Posted
Don't those require you to run a .exe from the USB drive to decrypt the partition on it? I very much hope you've got that blocked...

 

Yes, running executables would be blocked. I've always used Bitlocker drives myself but I believe you can buy drives with biometrics, pre-set passwords and all sorts these days but I guess all of them will require some sort of exe to run?

Posted
It will prompt you to encrypt it anyway, so you'd effectively have a double-encrypted device. I encountered this with hardware-encrypted USB devices, which then had to be encrypted again with BitLocker, so the user had to put in two passwords to access the data.

 

That's excellent, thanks for confirming :-)

Posted
Yes, running executables would be blocked. I've always used Bitlocker drives myself but I believe you can buy drives with biometrics, pre-set passwords and all sorts these days but I guess all of them will require some sort of exe to run?

 

I've used the biometric ones before, also one which had physical buttons on it to enter a code. In each instance, you unlock the drive then have 10 seconds to plug it in before it locks again. As far as the computer is concerned, they are exactly the same as a drive which hasn't been encrypted at all, so if you have a Bitlocker policy, it won't allow them to work. They are, however, the only way I found of securing documents for someone who was swapping between Windows in school and Mac at home.

Posted
The policy says: "Removable storage devices such as USB memory sticks must be checked with antivirus software and only be used if they are found to be clear of viruses. Files within computer storage areas / removable storage may be monitored to ensure no inappropriate content is being stored or brought into school."

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...