General Good Practices on the Use of Portable Storage Media (for Students)

In general, portable storage media, such as USB drives and external SSDs or HDDs, should be protected by reasonable measures, especially those containing sensitive and confidential information. These media are prone to loss and theft, and should be used carefully.


Guidelines:

  1. Downloading
    - Confidential information should only be downloaded to portable storage media with proper endorsement. Those who downloaded the confidential information should take reasonable measures to protect the confidentiality.
     
  2. Storage and Transit
    - To protect the information from being leaked during transit, the data in the portable storage media should be encrypted. Most Office, zip and Acrobat tools support AES 256-bit encryption. The password for decryption should be sent to the recipient through a separate channel.
    - Physically label the portable storage media with contact information so that it could be returned to the owner if it is found.
     
  3. Using media on foreign computers
    - Extra care must be taken to connect the portable storage media to public computers or computers from an unknown source. Users should ensure sufficient security measures, e.g. anti-virus software and firewall, are installed on the computer.
     
  4. Loss and Theft
    - Loss and theft of the portable storage media should be reported to the custodian of the data as soon as possible.
     
  5. Disposal
    - Disposal of the portable storage media should be done when the data is completely removed or physically purged.



Tools:

Both VeraCrypt or BitLocker support AES 256-bit encryption, which is a standard adopted by the US government. Access to the encrypted volume or device is password protected. AES encryption to portable devices is done on-the-fly. For more information on VeraCrypt and BitLocker, please refer to Data Protection with VeraCrypt or Data Protection with BitLocker respectively.