Removable Storage Policy
Last updated: 23 August 2026
Purpose
OMSUK seeks to minimise the security, privacy and malware risks associated with removable storage.
Secure electronic transfer is preferred wherever practical. Removable storage may nevertheless be required for diagnostic work, data recovery, system installation, offline backup or circumstances in which electronic transfer is unavailable or inappropriate.
Scope
This policy applies to removable storage used by OMSUK personnel in connection with client or company information, including:
USB flash drives.
External hard drives and solid-state drives.
Memory cards.
Optical media.
Client-owned storage devices.
Bootable diagnostic and installation media.
General requirements
Removable storage must only be used where there is a legitimate business or technical requirement.
Before using removable storage, OMSUK will consider whether the information can be transferred more securely using an approved electronic service.
The amount of information placed on removable storage must be limited to what is reasonably necessary for the task.
OMSUK-owned media
Where personal, confidential or commercially sensitive information must be stored on OMSUK-owned removable media:
The media must be approved for business use.
Appropriate encryption must be used.
The encryption password or recovery information must be communicated separately from the device.
The media must be protected against loss, theft, unauthorised access and physical damage.
The media must not be left unattended in an insecure location.
Information must be securely erased when it is no longer required.
Loss, theft or suspected unauthorised access must be reported immediately.
Where appropriate, OMSUK will maintain a record of the media, its custodian, its purpose and its return or secure disposal.
Client-owned media
Client-owned media may be used where required for technical support, diagnostics, data recovery or the return of client information.
Client media will be treated as potentially untrusted and may be scanned or examined using appropriate security controls before files are opened or transferred.
OMSUK may decline to connect media that appears damaged, compromised, counterfeit or otherwise unsafe.
Unless otherwise agreed, ownership of and responsibility for retaining client-owned media remains with the client. OMSUK will take reasonable care of the media while it is in our possession but clients should maintain an appropriate backup wherever possible.
Diagnostic and installation media
Removable media used solely for operating-system installation, approved software installation, firmware updates, diagnostics or recovery tools may be used where required.
Diagnostic media must be obtained from a trusted source, maintained appropriately and protected against unauthorised modification.
Client information must not be retained on diagnostic or installation media after the work has been completed unless there is a documented reason to do so.
Malware protection
Removable storage may be scanned using approved security tools before and after use.
Files that appear malicious, unsafe or inconsistent with their expected type may be blocked, quarantined or deleted. Where appropriate, OMSUK will notify the client and agree an alternative transfer method.
Auto-run or automatic execution of content from removable media must not be relied upon.
Transport
Where removable media contains personal or confidential information, it must be transported securely.
Depending on the sensitivity of the information, this may include:
Delivery by an authorised OMSUK representative.
Collection by an authorised client representative.
Use of an appropriate tracked and signed-for courier service.
Protective packaging.
Encryption of the media.
Separate communication of passwords or recovery details.
The transfer method should be proportionate to the sensitivity and volume of the information.
Retention and erasure
Information held temporarily on removable media must be removed when the transfer, diagnostic or recovery work has been completed and retention is no longer required.
Media being reused must be securely erased using a method appropriate to the device and sensitivity of the information.
Where secure erasure is not possible or the media has failed, it must be physically destroyed or returned to the client for secure disposal.
Incidents and exceptions
Lost, stolen, misdirected, infected or unexpectedly accessed removable media must be reported to OMSUK immediately.
Any suspected exposure of personal information will be assessed under OMSUK’s incident-management and personal-data-breach procedures.
An exception to this policy may be approved where there is a documented operational need and appropriate alternative safeguards have been applied.
Questions about this policy can be sent to hello@omsuk.com.