Solved

Organisation Security

Posted on 2012-03-30
12
165 Views
Last Modified: 2013-10-21
Is there a way or program to block user frm using USB/DVD to theft away the data or to avoid virus spreading from USB pendrive?
I knew by using 2008 AD policy, it can be done, but when user bring their notebook back to home, nothing can be controlled.
How to have a strict organisation security?
0
Comment
Question by:swpui
  • 5
  • 3
  • 3
  • +1
12 Comments
 
LVL 10

Expert Comment

by:Murali
ID: 37785963
you can disable at registry level for all the computers in a domain...

You just need to change the following registry key to any other value (less)...

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR\Start

By default is 4.. which means the removable devices are read and write.. you can change to 1.

It disables the flash devices..

You can experiment on any computer.. Good luck
0
 

Author Comment

by:swpui
ID: 37786003
tried before, sometimes it will auto enable the flash drive when u use a new one
0
 
LVL 10

Expert Comment

by:Murali
ID: 37786102
yes.. by default it will 4.. means that it is enabled...
0
 
LVL 18

Expert Comment

by:irweazelwallis
ID: 37786260
you can use all the GPO settings to disable removable storage and hide the drives letter (using group policy preferences)

You can also get 3rd party products like lumension that will control registered USB devices. this will enable you to control whether they are at home or on the corporate LAN. this is probably the path you want to go down as this means you can control which USB sticks can be used and what for.

when you say bring their notebooks back i presume you are still talking about corporate notebooks.
0
 

Author Comment

by:swpui
ID: 37786274
I mean after I set to 1, I tested with flashdiskA, it was blocked. Later i test with flashdiskB, it can be read and I checked the regedit, it auto changed to 4.
0
 
LVL 10

Expert Comment

by:Murali
ID: 37786375
can try set it to 3
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 18

Expert Comment

by:irweazelwallis
ID: 37786440
have you tried using the group policy settings

Computer configuration\administrative templates\system\removable storage access

set these to disabled

also the same location for user configuration
0
 

Expert Comment

by:Y-IT
ID: 37790661
Hello dear,

have you tried to use a Device Control program such Symantec EndPoint Protection that will enable you to block Device in general or by ID.

there are a lot of companies in market providing Device control Solution which enable you to control devices which is allowed and which is not.
0
 

Author Comment

by:swpui
ID: 37794365
If I have an XP pc, it can't be controlled using AD group policy setting
0
 
LVL 18

Accepted Solution

by:
irweazelwallis earned 500 total points
ID: 37794915
you can try this custom ADM that was published by Petri

http://www.petri.co.il/disable_usb_disks_with_gpo.htm

failing that you are best off heading down the 3rd party product
0
 

Author Comment

by:swpui
ID: 37853963
This is not working in XP environment!
0
 

Author Closing Comment

by:swpui
ID: 39587104
not really good
0

Featured Post

Superior storage. Superior surveillance.

WD Purple drives are built for 24/7, always-on, high-definition security systems. With support for up to 8 hard drives and 32 cameras, WD Purple drives are optimized for surveillance.

Join & Write a Comment

Article by: btan
Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now