Removable media controls
Policy and technical rules for USB drives, external disks, memory cards and tapes: whether they may be used at all, which devices are approved, how they are encrypted and how they are tracked.
Removable media controls govern portable storage that can carry data outside the systems built to protect it: USB flash drives, external hard disks, memory cards and backup tapes. Policy decides whether removable media may be used at all for a given data classification, and technology enforces that decision through device control that blocks unapproved hardware, allow lists of approved drives, and mandatory encryption of anything written. NIST SP 800-53 Rev. 5 covers the area in its Media Use control (MP-7).
These controls sit within the handling requirements that a classification label triggers, alongside marking and labelling of the media, logged transport, and sanitisation before reuse or disposal. They overlap with data loss prevention, which can inspect what is copied to a device, and with endpoint security agents that apply device policy. The risk also runs inwards: a drive can carry malware onto an isolated network, which is the route commonly cited for Stuxnet.
Exam relevance: a scenario is likely to describe data lost on a USB drive or tape, or malware arriving on one, and ask for the most effective control. Candidates are expected to weigh encrypting approved media against blocking it outright, to tie the level of restriction to the data’s classification, and to notice that a written policy with no technical enforcement tends to be the weaker answer.