{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/plan-removable-media-controls-business-use-malware-sanitization/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/",
        "slug": "plan-removable-media-controls-business-use-malware-sanitization",
        "url": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/plan-removable-media-controls-business-use-malware-sanitization/"
        },
        "title": "Plan removable-media controls around business use, malware risk, and sanitization",
        "summary": "Removable media can carry essential recovery data, sensitive records, and malicious content across trust boundaries. Define approved uses, managed media, encryption, scanning, transfer stations, custody, retention, and sanitization by risk.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-17T12:50:00+00:00",
        "modified_at": "2026-08-17T19:22:10+00:00",
        "reviewed_on": "2026-08-17",
        "reading_minutes": 3,
        "word_count": 639,
        "potentially_affected": "USB storage and removable media; endpoints and servers; backup and recovery workflows; operational systems; service technicians; sensitive data transfers; malware controls; encryption; custody records; reuse; and disposal.",
        "dse_recommendation": "Map legitimate media workflows, prohibit unapproved use, issue managed encrypted media, constrain read and write paths, inspect content, maintain custody, protect recovery copies, and sanitize or destroy media using verified methods.",
        "primary_source": {
            "name": "CISA: How to Protect the Data That is Stored on Your Devices",
            "url": "https://www.cisa.gov/resources-tools/training/how-protect-data-stored-your-devices",
            "published_on": null,
            "authority": "Cybersecurity and Infrastructure Security Agency"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts: media control continues through its final disposition</h2>\n<p>NIST <a href=\"https://csrc.nist.gov/pubs/sp/800/88/r2/final\" target=\"_blank\" rel=\"noopener noreferrer\">SP 800-88 Rev. 2, Guidelines for Media Sanitization</a>, frames sanitization as a program based on information sensitivity, media type, intended disposition, organizational risk, available techniques, verification, and documentation. Clear, purge, and destroy are categories whose suitability depends on the media and the organization&#8217;s requirements.</p>\n<p>CISA&#8217;s <a href=\"https://www.cisa.gov/resources-tools/training/how-protect-data-stored-your-devices\" target=\"_blank\" rel=\"noopener noreferrer\">guidance on protecting data stored on devices</a> emphasizes understanding what data is present, controlling access, using encryption, maintaining backups, and securely disposing of devices and media. Those practices address confidentiality and recovery but do not replace malware prevention, safe transfer, or system-specific operating restrictions.</p>\n<p>The sources do not require one universal choice among prohibition, authorization, encryption, scanning, write restriction, managed media, or physical destruction. A recovery team, service technician, isolated operational system, and ordinary office user can have different legitimate needs and consequences.</p>\n\n<h2>DSE recommendation: govern each transfer from issuance through sanitization</h2>\n<p>Begin with the business workflow. Eliminate casual use, then provide a controlled path for the transfers and recovery functions that remain necessary.</p>\n<ol>\n<li><strong>Map approved use cases.</strong> Identify recovery media, configuration transfer, evidence collection, field service, software installation, offline update, regulated export, and customer delivery. For each, record data class, source and destination trust zones, owner, frequency, retention, and what happens if the media is lost or contaminated.</li>\n<li><strong>Set a controlled default.</strong> Block or restrict unapproved removable storage through supported endpoint and application controls. Distinguish storage from keyboards, authentication devices, serial adapters, cameras, and other USB classes. Provide a documented exception route so necessary work does not move to invisible personal media.</li>\n<li><strong>Issue managed media.</strong> Use organization-owned, uniquely identified media with appropriate capacity, hardware or software encryption, recovery-key custody, tamper handling, and assignment records. Limit who may receive it and where it may connect. Do not rely on a printed label as the only inventory control.</li>\n<li><strong>Control the transfer station.</strong> Where risk justifies it, use a hardened intermediary with current protection, restricted networking, disabled autorun behavior, content inspection, logging, and a reset or rebuild process. Define separate paths for inbound and outbound material and a quarantine decision for suspicious files.</li>\n<li><strong>Minimize and verify content.</strong> Transfer only required files, preserve hashes or signatures when applicable, scan before and after movement, and validate the destination result. Treat encrypted archives and unsupported formats as unresolved until they can be inspected through an approved method.</li>\n<li><strong>Maintain custody and recovery.</strong> Record issue, transfer, return, storage, loss, and incident events. Protect recovery media from the same event as the production system, test that it can be read on approved equipment, and ensure encryption keys remain available during an outage.</li>\n<li><strong>Sanitize according to media and disposition.</strong> Select a clear, purge, or destroy method supported for the exact media and risk. Verify the outcome, record the method and operator, and use qualified destruction or recycling services where required. Account for failed and damaged media that cannot accept ordinary commands.</li>\n</ol>\n<p>Include removable media in incident response. Define when a device is isolated, who may handle it, how a forensic image or hash is obtained when appropriate, how exposed systems are identified, and when credentials or data transfers require investigation. Do not reconnect suspected media merely to determine whether it still works.</p>\n<p><strong>Factual boundary:</strong> Sanitization effectiveness depends on media technology, device implementation, condition, encryption, and intended disposition. Antivirus scanning cannot guarantee a file is safe, and encryption does not prevent an authorized endpoint from reading malicious content. Legal, contractual, records, safety, and vendor requirements can change the appropriate control.</p>\n<p>Measure personal or unknown media detections, approved transfers, inspection failures, lost media, recovery-read tests, overdue returns, sanitization verification, and exceptions past expiry. The target is a usable controlled path with traceable custody—not a policy statement that ignores the work people must perform.</p>\n\n<h2>Official references</h2>\n<ul>\n<li>NIST, <a href=\"https://csrc.nist.gov/pubs/sp/800/88/r2/final\" target=\"_blank\" rel=\"noopener noreferrer\"><em>SP 800-88 Rev. 2: Guidelines for Media Sanitization</em></a>.</li>\n<li>CISA, <a href=\"https://www.cisa.gov/resources-tools/training/how-protect-data-stored-your-devices\" target=\"_blank\" rel=\"noopener noreferrer\"><em>How to Protect the Data That is Stored on Your Devices</em></a>.</li>\n</ul>",
        "content_text": "Source facts: media control continues through its final disposition\nNIST SP 800-88 Rev. 2, Guidelines for Media Sanitization, frames sanitization as a program based on information sensitivity, media type, intended disposition, organizational risk, available techniques, verification, and documentation. Clear, purge, and destroy are categories whose suitability depends on the media and the organization’s requirements.\nCISA’s guidance on protecting data stored on devices emphasizes understanding what data is present, controlling access, using encryption, maintaining backups, and securely disposing of devices and media. Those practices address confidentiality and recovery but do not replace malware prevention, safe transfer, or system-specific operating restrictions.\nThe sources do not require one universal choice among prohibition, authorization, encryption, scanning, write restriction, managed media, or physical destruction. A recovery team, service technician, isolated operational system, and ordinary office user can have different legitimate needs and consequences.\n\nDSE recommendation: govern each transfer from issuance through sanitization\nBegin with the business workflow. Eliminate casual use, then provide a controlled path for the transfers and recovery functions that remain necessary.\n\nMap approved use cases. Identify recovery media, configuration transfer, evidence collection, field service, software installation, offline update, regulated export, and customer delivery. For each, record data class, source and destination trust zones, owner, frequency, retention, and what happens if the media is lost or contaminated.\nSet a controlled default. Block or restrict unapproved removable storage through supported endpoint and application controls. Distinguish storage from keyboards, authentication devices, serial adapters, cameras, and other USB classes. Provide a documented exception route so necessary work does not move to invisible personal media.\nIssue managed media. Use organization-owned, uniquely identified media with appropriate capacity, hardware or software encryption, recovery-key custody, tamper handling, and assignment records. Limit who may receive it and where it may connect. Do not rely on a printed label as the only inventory control.\nControl the transfer station. Where risk justifies it, use a hardened intermediary with current protection, restricted networking, disabled autorun behavior, content inspection, logging, and a reset or rebuild process. Define separate paths for inbound and outbound material and a quarantine decision for suspicious files.\nMinimize and verify content. Transfer only required files, preserve hashes or signatures when applicable, scan before and after movement, and validate the destination result. Treat encrypted archives and unsupported formats as unresolved until they can be inspected through an approved method.\nMaintain custody and recovery. Record issue, transfer, return, storage, loss, and incident events. Protect recovery media from the same event as the production system, test that it can be read on approved equipment, and ensure encryption keys remain available during an outage.\nSanitize according to media and disposition. Select a clear, purge, or destroy method supported for the exact media and risk. Verify the outcome, record the method and operator, and use qualified destruction or recycling services where required. Account for failed and damaged media that cannot accept ordinary commands.\n\nInclude removable media in incident response. Define when a device is isolated, who may handle it, how a forensic image or hash is obtained when appropriate, how exposed systems are identified, and when credentials or data transfers require investigation. Do not reconnect suspected media merely to determine whether it still works.\nFactual boundary: Sanitization effectiveness depends on media technology, device implementation, condition, encryption, and intended disposition. Antivirus scanning cannot guarantee a file is safe, and encryption does not prevent an authorized endpoint from reading malicious content. Legal, contractual, records, safety, and vendor requirements can change the appropriate control.\nMeasure personal or unknown media detections, approved transfers, inspection failures, lost media, recovery-read tests, overdue returns, sanitization verification, and exceptions past expiry. The target is a usable controlled path with traceable custody—not a policy statement that ignores the work people must perform.\n\nOfficial references\n\nNIST, SP 800-88 Rev. 2: Guidelines for Media Sanitization.\nCISA, How to Protect the Data That is Stored on Your Devices.",
        "content_markdown": "## Source facts: media control continues through its final disposition\n\nNIST [SP 800-88 Rev. 2, Guidelines for Media Sanitization](https://csrc.nist.gov/pubs/sp/800/88/r2/final), frames sanitization as a program based on information sensitivity, media type, intended disposition, organizational risk, available techniques, verification, and documentation. Clear, purge, and destroy are categories whose suitability depends on the media and the organization’s requirements.\n\nCISA’s [guidance on protecting data stored on devices](https://www.cisa.gov/resources-tools/training/how-protect-data-stored-your-devices) emphasizes understanding what data is present, controlling access, using encryption, maintaining backups, and securely disposing of devices and media. Those practices address confidentiality and recovery but do not replace malware prevention, safe transfer, or system-specific operating restrictions.\n\nThe sources do not require one universal choice among prohibition, authorization, encryption, scanning, write restriction, managed media, or physical destruction. A recovery team, service technician, isolated operational system, and ordinary office user can have different legitimate needs and consequences.\n\n## DSE recommendation: govern each transfer from issuance through sanitization\n\nBegin with the business workflow. Eliminate casual use, then provide a controlled path for the transfers and recovery functions that remain necessary.\n\n- Map approved use cases. Identify recovery media, configuration transfer, evidence collection, field service, software installation, offline update, regulated export, and customer delivery. For each, record data class, source and destination trust zones, owner, frequency, retention, and what happens if the media is lost or contaminated.\n\n- Set a controlled default. Block or restrict unapproved removable storage through supported endpoint and application controls. Distinguish storage from keyboards, authentication devices, serial adapters, cameras, and other USB classes. Provide a documented exception route so necessary work does not move to invisible personal media.\n\n- Issue managed media. Use organization-owned, uniquely identified media with appropriate capacity, hardware or software encryption, recovery-key custody, tamper handling, and assignment records. Limit who may receive it and where it may connect. Do not rely on a printed label as the only inventory control.\n\n- Control the transfer station. Where risk justifies it, use a hardened intermediary with current protection, restricted networking, disabled autorun behavior, content inspection, logging, and a reset or rebuild process. Define separate paths for inbound and outbound material and a quarantine decision for suspicious files.\n\n- Minimize and verify content. Transfer only required files, preserve hashes or signatures when applicable, scan before and after movement, and validate the destination result. Treat encrypted archives and unsupported formats as unresolved until they can be inspected through an approved method.\n\n- Maintain custody and recovery. Record issue, transfer, return, storage, loss, and incident events. Protect recovery media from the same event as the production system, test that it can be read on approved equipment, and ensure encryption keys remain available during an outage.\n\n- Sanitize according to media and disposition. Select a clear, purge, or destroy method supported for the exact media and risk. Verify the outcome, record the method and operator, and use qualified destruction or recycling services where required. Account for failed and damaged media that cannot accept ordinary commands.\n\nInclude removable media in incident response. Define when a device is isolated, who may handle it, how a forensic image or hash is obtained when appropriate, how exposed systems are identified, and when credentials or data transfers require investigation. Do not reconnect suspected media merely to determine whether it still works.\n\nFactual boundary: Sanitization effectiveness depends on media technology, device implementation, condition, encryption, and intended disposition. Antivirus scanning cannot guarantee a file is safe, and encryption does not prevent an authorized endpoint from reading malicious content. Legal, contractual, records, safety, and vendor requirements can change the appropriate control.\n\nMeasure personal or unknown media detections, approved transfers, inspection failures, lost media, recovery-read tests, overdue returns, sanitization verification, and exceptions past expiry. The target is a usable controlled path with traceable custody—not a policy statement that ignores the work people must perform.\n\n## Official references\n\n- NIST, [SP 800-88 Rev. 2: Guidelines for Media Sanitization](https://csrc.nist.gov/pubs/sp/800/88/r2/final).\n\n- CISA, [How to Protect the Data That is Stored on Your Devices](https://www.cisa.gov/resources-tools/training/how-protect-data-stored-your-devices)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/",
                "url": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-17"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Plan removable-media controls around business use, malware risk, and sanitization",
                        "item": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/#article",
                "identifier": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/",
                "url": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/",
                "headline": "Plan removable-media controls around business use, malware risk, and sanitization",
                "description": "Removable media can carry essential recovery data, sensitive records, and malicious content across trust boundaries. Define approved uses, managed…",
                "abstract": "Removable media can carry essential recovery data, sensitive records, and malicious content across trust boundaries. Define approved uses, managed media, encryption, scanning, transfer stations, custody, retention, and sanitization by risk.",
                "articleBody": "Source facts: media control continues through its final disposition\nNIST SP 800-88 Rev. 2, Guidelines for Media Sanitization, frames sanitization as a program based on information sensitivity, media type, intended disposition, organizational risk, available techniques, verification, and documentation. Clear, purge, and destroy are categories whose suitability depends on the media and the organization’s requirements.\nCISA’s guidance on protecting data stored on devices emphasizes understanding what data is present, controlling access, using encryption, maintaining backups, and securely disposing of devices and media. Those practices address confidentiality and recovery but do not replace malware prevention, safe transfer, or system-specific operating restrictions.\nThe sources do not require one universal choice among prohibition, authorization, encryption, scanning, write restriction, managed media, or physical destruction. A recovery team, service technician, isolated operational system, and ordinary office user can have different legitimate needs and consequences.\n\nDSE recommendation: govern each transfer from issuance through sanitization\nBegin with the business workflow. Eliminate casual use, then provide a controlled path for the transfers and recovery functions that remain necessary.\n\nMap approved use cases. Identify recovery media, configuration transfer, evidence collection, field service, software installation, offline update, regulated export, and customer delivery. For each, record data class, source and destination trust zones, owner, frequency, retention, and what happens if the media is lost or contaminated.\nSet a controlled default. Block or restrict unapproved removable storage through supported endpoint and application controls. Distinguish storage from keyboards, authentication devices, serial adapters, cameras, and other USB classes. Provide a documented exception route so necessary work does not move to invisible personal media.\nIssue managed media. Use organization-owned, uniquely identified media with appropriate capacity, hardware or software encryption, recovery-key custody, tamper handling, and assignment records. Limit who may receive it and where it may connect. Do not rely on a printed label as the only inventory control.\nControl the transfer station. Where risk justifies it, use a hardened intermediary with current protection, restricted networking, disabled autorun behavior, content inspection, logging, and a reset or rebuild process. Define separate paths for inbound and outbound material and a quarantine decision for suspicious files.\nMinimize and verify content. Transfer only required files, preserve hashes or signatures when applicable, scan before and after movement, and validate the destination result. Treat encrypted archives and unsupported formats as unresolved until they can be inspected through an approved method.\nMaintain custody and recovery. Record issue, transfer, return, storage, loss, and incident events. Protect recovery media from the same event as the production system, test that it can be read on approved equipment, and ensure encryption keys remain available during an outage.\nSanitize according to media and disposition. Select a clear, purge, or destroy method supported for the exact media and risk. Verify the outcome, record the method and operator, and use qualified destruction or recycling services where required. Account for failed and damaged media that cannot accept ordinary commands.\n\nInclude removable media in incident response. Define when a device is isolated, who may handle it, how a forensic image or hash is obtained when appropriate, how exposed systems are identified, and when credentials or data transfers require investigation. Do not reconnect suspected media merely to determine whether it still works.\nFactual boundary: Sanitization effectiveness depends on media technology, device implementation, condition, encryption, and intended disposition. Antivirus scanning cannot guarantee a file is safe, and encryption does not prevent an authorized endpoint from reading malicious content. Legal, contractual, records, safety, and vendor requirements can change the appropriate control.\nMeasure personal or unknown media detections, approved transfers, inspection failures, lost media, recovery-read tests, overdue returns, sanitization verification, and exceptions past expiry. The target is a usable controlled path with traceable custody—not a policy statement that ignores the work people must perform.\n\nOfficial references\n\nNIST, SP 800-88 Rev. 2: Guidelines for Media Sanitization.\nCISA, How to Protect the Data That is Stored on Your Devices.",
                "datePublished": "2026-08-17T12:50:00+00:00",
                "dateModified": "2026-08-17T19:22:10+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/plan-removable-media-controls-business-use-malware-sanitization/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Plan removable-media controls around business use, malware risk, and sanitization"
                },
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT",
                    "Playbook",
                    "Advisory priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 639,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "CISA: How to Protect the Data That is Stored on Your Devices",
                    "url": "https://www.cisa.gov/resources-tools/training/how-protect-data-stored-your-devices"
                }
            }
        ]
    }
}