>> There should be an absolute policy about unknown devices. Breach should warrant severe censure.
That was exactly the policy in my latter days in Civil Service. Breach would be gross misconduct. Negligible risk to or in our own work but we were part of wider network and ultimately part of government secure intranet.
Problem for us was that we had visitors making presentations to the Quango's formal meetings. Inevitably they'd want to be tweaking stuff until last minute and bring final version to meeting. Problem solved with a standalone laptop that was incapable of connection to gsi.
Even in charitable sector where I work now USB drives are banned and the slots on the PC's disabled.
|