Risk
2/19/2010
02:14 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Military Lifts Removable Media Ban, Imposes Limits

The new policies set strict limits on how thumb drives and other removable media may be used.

The Department of Defense has loosened its outright ban on the use of removable media, but only under strictly limited circumstances and only as a last resort.

In new guidance issued last Friday but first reported this week, U.S. Strategic Command laid out a number of new requirements for the use of any removable media. According to the guidance, only Department of Defense computers in strict compliance with secure hardware requirements will be able to use removable media.

The military had instituted a ban on thumb drives and other removable media such as flash memory cards for cameras in late 2008 after a rash of malware spread by removable media hit the troops.

Those concerns appear to persist. "This is not a return to 'business as usual,'" Vice Adm. Carl Mauney, deputy commander of U.S. Strategic Command, said in an e-mail through a spokesman. However, Mauney said, after "extensive testing of mitigation measures," the military decided it could again allow some removable media -- withing strict limits.

In no way does the lifted ban mean that soldiers will be able to use thumb drives for any purpose. Under the guidance, removable media will be allowed only in "mission-essential operations" and with strict attention to compliance, and even then only to transfer data between locations when "other authorized network resources are unavailable."

After passing the acceptable use test, the hardware must pass its own battery of tests. Soldiers will be able to use only approved, government-purchased and -owned hardware that has been scanned and wiped of any malicious software beforehand and that prevents unauthorized use.

For those who wish to try to skirt the requirements, the military plans to begin random auditing of users and drives. The ban on using personally owned devices on DoD networks, or DoD devices on non-DoD networks, will stay in place.

Additionally, it's possible that individual combatant commands, services, and agencies may issue their own additional restrictions, as the guidance tasks them with creating their own "approval authorities."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Join Dark Reading community editor Marilyn Cohodas and her guest, David Shearer, (ISC)2 Chief Executive Officer, as they discuss issues that keep IT security professionals up at night, including results from the recent 2016 Black Hat Attendee Survey.