Monday, November 24, 2008

The DoD's new USB policy

This news was rampant on Friday, but I'm just getting around to posting a thought about it. If you did not hear, the DoD is prohibiting USB drives (connections?) on all DoD machines. Apparently, they are fighting a worm/malware issues that may have been exasperated by the auto-run feature of many usb drives. I agree, it's probably NOT a bad policy to have. When I was working for a company, I wish I could have enacted policy like that. It would have cut down on the headaches.

However, my question is, can't the anti-virus software be configured to scan any USB connection to the computer? Wouldn't that help in the fight? I'm pretty certain that all DoD machines are required to have AV software installed and running. Wouldn't that help mitigate the risk.

