Sekit CSF · Endpoint Security · Policy
RCF-0157Removable media control
The use of removable storage devices such as USB drives is formally restricted to authorised business needs
Mapping at a glance
RCF-0157Removable media controlEndpoint Security · Policy
RCF-0157 maps to 4 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.1Policies for information securitysupportsSekit's Removable media control policy, one of A.5.1's topic-specific policies, restricts USB drives and similar storage to approved, justified business needs only.A.7.10Storage mediasupportsThis policy control restricts USB drives and other removable storage to approved, justified business uses only, covering the use slice of A.7.10's lifecycle while RCF-0159 performs the restriction at OS level.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Local admin and removable-media controls
The rules on who may have administrator rights on their own device and on the use of USB sticks and external drives.
From the Sekit evidence catalog
This topic through the other lenses
All Endpoint Security controls
Ask Sekura: “What evidence proves RCF-0157?”
Also via MCP, free with account