It can allow, restrict, or monitor removable storage, printers, cameras, human-interface devices, and wired or short-range wireless connections according to device identity or class, user, endpoint, operation, and context. The label is variable across operating systems and security products.
Device control reduces paths for malicious code, unauthorized data transfer, alternate boot or debugging, and direct memory access. Policy should begin with operational need because blocking a port or peripheral can also interrupt accessibility, maintenance, backup, or essential workflows.
Key points
Discover use and riskInventory interfaces and connected-device classes, identify legitimate owners and workflows, classify data that may cross them, and assess malware, loss, impersonation, debugging, and memory-access scenarios.
Enforce specific permissionsPrefer rules for approved devices, users, endpoints, and operations such as read, write, execute, print, synchronize, or charge instead of an unexplained universal block.
Protect and verifyUse encryption and malware controls where appropriate, log meaningful connection and transfer events, manage exceptions and expiry, test policy on supported hardware, and investigate attempted bypass.
Important limitationA permitted identifier does not prove that a peripheral is safe; identifiers can be generic or spoofed, and a trusted device can be compromised. Controls may also miss unsupported interfaces, encrypted transfers, photographs, or data moved through allowed applications.