The shop floor · 2.3
Removable media, and why bans fail
Removable media, and why bans fail. What the requirement says, what it means in practice, and what an assessor will ask.
For a related human-factors concept, chronemics provides additional context for interpreting behaviour without jumping to conclusions.
For an independent reference point, see OWASP Internet of Things project.
The reality
Memory sticks are how programs reach machines
In a large proportion of workshops this is simply the transfer mechanism, established long before anybody mentioned a standard, and it works. Treating it as a discipline problem misdescribes the situation.
The requirement does not prohibit removable media. It requires that its use be controlled, that devices be identified, and that data on them be protected.
Four arrangements
From loosest to tightest
Any device, uncontrolled. The current state in many workshops and the one that cannot be evidenced.
Issued devices only. A numbered set, signed out, with anything else blocked. Cheap, enforceable at the port, and it produces a record.
Issued and encrypted. The same, with hardware encryption, which addresses loss as well as use.
No removable media, with a replacement route. Ports blocked and a network or brokered transfer path provided.
The fourth is only available where the replacement genuinely works on all three shifts, which the blog entry on the operator's view explains.
Sanitisation
Reused devices carry the last job
A stick used for one customer's program and then another's has carried information between them unless it was cleared. Deleting is not clearing.
Either dedicate devices, or clear them with a documented method, or destroy them at end of life with a record. All three are acceptable and none happens by default.
The port block
What blocking actually does
Blocking ports on modern equipment is straightforward. Blocking them on a controller from an earlier decade is frequently not possible without voiding a maintenance agreement, which returns to the four options in the entry on legacy machines.
Where the port cannot be blocked, control moves to the device side: issued sticks only, and a physical arrangement making unofficial ones awkward.
Logging
Record the transfer, not the port
Machines generally cannot tell you what was inserted. What can be recorded is the authorisation and release of the file before it travels, which happens on a system that does keep records.
That record answers the assessor's question about what reached which machine, and it exists independently of the equipment.
Personal devices
The phone charging in the controller
Common, harmless in intent, and a data path. It also draws attention in an assessment out of proportion to its risk, because it demonstrates that the port arrangement is not what the procedure says.
Provide charging points that are not data ports. The problem largely disappears.
Writing the procedure
One page, on the wall
Which devices may be used, where they are kept, who issues them, what happens when one is lost, and how they are cleared. Posted where the transfers happen rather than filed.
An assessor reading a wall notice that matches what an operator says is a stronger result than a policy document that neither has seen.
Incoming media
Sticks arriving from outside
A customer or a vendor hands over a device. It is now in your environment and it came from somewhere you do not control.
Handle incoming media through one route with a scan and a copy onto your own device, and return or retain the original deliberately. This is a two-minute procedure that prevents a category of problem entirely.
Loss
What happens when one goes missing
Encrypted, it is an inconvenience. Unencrypted and carrying covered information, it is potentially the reportable incident the blog entry on what counts describes.
Which is the strongest practical argument for the encrypted option and worth making in the budget case rather than in the aftermath.
Colour coding
The cheapest control in this section
Issued devices in one colour, kept in one place, everything else obviously not one of them. It costs nothing, it makes an unauthorised device visible across a workshop, and supervisors enforce it without being asked because they can see it.
The count
Know how many you have
A numbered set with a register. When one is missing you know, which is the difference between a loss you can report and a loss you never learn about.
Also
Elsewhere in the shop floor
- What the three levels are, and which appliesThe level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.
- Reading the clause that binds youReading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.
- Which systems are in scopeWhich systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.
- Self-assessment, and why the scores driftedSelf-assessment, and why the scores drifted. What the requirement says, what it means in practice, and what an assessor will ask.
- Who assesses you, and how each kind worksWho assesses you, and how each kind works. What the requirement says, what it means in practice, and what an assessor will ask.
- What the standard does not requireWhat the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.
- Machines older than the requirementsA control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.
- Drawings, job packets and paperDrawings, job packets and paper. What the requirement says, what it means in practice, and what an assessor will ask.
- Vendor remote accessVendor remote access. What the requirement says, what it means in practice, and what an assessor will ask.
- Technical data packages and what they containTechnical data packages and what they contain. What the requirement says, what it means in practice, and what an assessor will ask.
- Segmentation, and what it does not solveSegmentation, and what it does not solve. What the requirement says, what it means in practice, and what an assessor will ask.
- What insider risk actually coversWhat insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.
- What detection can and cannot establishWhat detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.
- Monitoring, and where the law constrains itMonitoring, and where the law constrains it. What the requirement says, what it means in practice, and what an assessor will ask.
- The fortnight around a departureThe fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.
- Privileged access, and who reviews itPrivileged access, and who reviews it. What the requirement says, what it means in practice, and what an assessor will ask.
- False positives, and what they costFalse positives, and what they cost. What the requirement says, what it means in practice, and what an assessor will ask.
- The documents an assessor reads firstThe documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.
- What counts as evidenceWhat counts as evidence. What the requirement says, what it means in practice, and what an assessor will ask.
- The findings that recurThe findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.
- Plans of action, and their limitsPlans of action, and their limits. What the requirement says, what it means in practice, and what an assessor will ask.
- What the assessment week is likeWhat the assessment week is like. What the requirement says, what it means in practice, and what an assessor will ask.
- The certificate, and what it coversThe certificate, and what it covers. What the requirement says, what it means in practice, and what an assessor will ask.