Removable Media Policy
01 Jan 2022
To establish requirements for the acceptable use, protection, and disposal of removable media in order to reduce the risk of loss, theft, or unauthorized disclosure of Kwanso and client confidential data.
All removable media that store or transmit confidential data as defined in the Kwanso Data Management Policy, and all Kwanso information systems capable of reading from or writing to such media. This policy applies to all employees of Kwanso and to all external parties who access Kwanso or client data. Removable media includes, but is not limited to, USB flash drives, external hard disk and solid-state drives, memory cards, optical media (CD, DVD, and Blu-ray), and mobile devices used for storage.
Kwanso's default position is that confidential data shall be stored and transferred through approved, access-controlled cloud services rather than removable media. The use of removable media to store or transfer confidential data is discouraged and is permitted only where there is a documented business need and no practical secure alternative.
- Removable media may only be used to store or transfer confidential data with prior approval from the IT Manager or the relevant system owner.
- Only Kwanso-issued and registered removable media may be connected to systems that process confidential data. Personal or unknown removable media must not be connected to such systems.
- Approved removable media shall be recorded in an inventory that identifies the device, its assigned owner, and its authorized purpose.
- All removable media used to store confidential data must be encrypted using strong cryptography in accordance with the Kwanso Cryptography Policy (AES-256).
- Encryption keys and passphrases must not be stored on, or transported together with, the media they protect.
- Removable media must only be used for legitimate business purposes and must not be used to circumvent Kwanso access controls, data management, or monitoring.
- Confidential data must not be copied to removable media except as authorized under this policy.
- Source code and associated materials must not be copied to removable media except where explicitly approved by the system owner, consistent with the Kwanso Access Control Policy.
- Users must not leave removable media unattended and must store it securely when not in use.
- Where confidential data must be physically transferred, the media must be encrypted and sent using a tracked and reliable delivery method.
- The sender must verify the identity and authorization of the recipient before any transfer of media.
- Removable media that is no longer required must be securely sanitized or physically destroyed before disposal or reuse, so that stored data cannot be recovered.
- Deletion or reformatting alone is not sufficient for media that has held confidential data.
- Records of removable media disposal shall be retained.
- Loss or theft of removable media containing confidential data must be reported to the IT Manager immediately, in accordance with the Kwanso Incident Response Policy.
Requests for an exception to this Policy must be submitted to the IT Manager for approval.
Any known violations of this policy should be reported to the IT Manager. Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and/or disciplinary action in accordance with company procedures up to and including termination of employment.