{"id":1151,"date":"2026-09-10T13:01:04","date_gmt":"2026-09-10T13:01:04","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1151"},"modified":"2026-09-10T13:01:04","modified_gmt":"2026-09-10T13:01:04","slug":"device-control","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/device-control\/","title":{"rendered":"Device Control"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: DEVICE CONTROL\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Device control decides what can plug into a company machine and what happens when it does. Most teams treat it as a USB switch. It is closer to a policy about every physical path in and out.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Endpoint<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Device control is the endpoint capability that governs removable media and peripherals: USB drives, external disks, phones in storage mode, SD cards, Bluetooth, printers and more. It enforces what each class of device is permitted to do on a managed machine, and it records what happened. It closes the physical path that network controls cannot see.<\/p>\n<\/div>\n\n<p>The reason it still matters in a cloud-first company is simple. Every other control assumes data moves over a network you can inspect. A USB drive does not.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#governs\">What device control governs<\/a><\/li>\n    <li><a href=\"#modes\">The four enforcement modes<\/a><\/li>\n    <li><a href=\"#dlp\">Device control and DLP<\/a><\/li>\n    <li><a href=\"#frameworks\">Where frameworks require it<\/a><\/li>\n    <li><a href=\"#osto\">How Osto handles device control<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"governs\">What device control governs<\/h2>\n\n<p>The category is wider than removable storage, which is where most policies stop and most gaps appear.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Device class<\/th><th>The risk it carries<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>USB mass storage<\/td><td>The obvious one. Bulk copy out, or malware in, with no network record either way<\/td><\/tr>\n    <tr><td>Phones in storage mode<\/td><td>A charging cable that is also a data path, which policies written for USB sticks routinely miss<\/td><\/tr>\n    <tr><td>External and portable drives<\/td><td>Large capacity, easy to lose, and rarely <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">encrypted<\/a> unless enforced<\/td><\/tr>\n    <tr><td>SD cards and card readers<\/td><td>Frequently excluded from policies that name USB explicitly<\/td><\/tr>\n    <tr><td>Bluetooth<\/td><td>File transfer and input devices, wireless and therefore invisible to a cable-based policy<\/td><\/tr>\n    <tr><td>Printers and scanners<\/td><td>Paper is an exfiltration format and a scanner is an ingestion one<\/td><\/tr>\n    <tr><td>Optical and legacy media<\/td><td>Rare, but still enumerated in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> and audit questionnaires<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"modes\" class=\"c-sage\">The four enforcement modes<\/h2>\n\n<p>Device control is not a switch. Treating it as one is why policies get disabled within a month of deployment.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 182\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Four device control enforcement modes: block, read only, allow listed and full access with logging.\">\n  <rect x=\"12\" y=\"24\" width=\"176\" height=\"86\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"100\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Block<\/text>\n  <text x=\"100\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">Device does not mount<\/text>\n  <text x=\"100\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#8f9ad4\">Safest, least popular<\/text>\n\n  <rect x=\"196\" y=\"24\" width=\"176\" height=\"86\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"284\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Read only<\/text>\n  <text x=\"284\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Data in, nothing out<\/text>\n  <text x=\"284\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">The usual sweet spot<\/text>\n\n  <rect x=\"380\" y=\"24\" width=\"176\" height=\"86\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"468\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Allow listed<\/text>\n  <text x=\"468\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Approved hardware only<\/text>\n  <text x=\"468\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">Identified by serial<\/text>\n\n  <rect x=\"564\" y=\"24\" width=\"184\" height=\"86\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"656\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Allow and log<\/text>\n  <text x=\"656\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Permitted, recorded<\/text>\n  <text x=\"656\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#a2603a\">Evidence, not prevention<\/text>\n\n  <rect x=\"12\" y=\"124\" width=\"736\" height=\"42\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"380\" y=\"150\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">Apply per device class and per group. One global setting is what gets exceptions, and exceptions become the policy.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<div class=\"callout\">\n  <p class=\"k\">Read only is the underused answer<\/p>\n  <p>Most business objections to device control are about getting files in, not out: a client hands over a drive, a contractor brings assets, someone restores from a backup. Read only permits all of that while closing the exfiltration path. Teams that jump straight to full block generate an exception queue, and an exception granted under deadline pressure is rarely reviewed again.<\/p>\n<\/div>\n\n<h2 id=\"dlp\" class=\"c-plum\">Device control and DLP<\/h2>\n\n<p>They overlap and are often confused. The distinction is that one asks about the destination and the other asks about the content.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th><\/th><th>Device control<\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">DLP<\/a><\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Question it answers<\/td><td>Can this device connect and write?<\/td><td>Can this specific data leave?<\/td><\/tr>\n    <tr><td>Decision basis<\/td><td>Device class, serial, user group<\/td><td>File content, classification, destination<\/td><\/tr>\n    <tr><td>Strength<\/td><td>Absolute on the physical path, and simple to evidence<\/td><td>Granular, and covers cloud and network paths too<\/td><\/tr>\n    <tr><td>Weakness<\/td><td>Blunt. It cannot tell a customer database from a holiday photo<\/td><td>Depends on classification quality, and needs tuning<\/td><\/tr>\n    <tr><td>Deployment effort<\/td><td>Policy set once, largely static<\/td><td>Ongoing, because rules follow how data actually moves<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Run both. Device control handles the path that carries the highest volume with the least visibility, and it does so on day one. DLP handles everything that leaves over a network, and it takes longer to get right.<\/p>\n\n<h2 id=\"frameworks\" class=\"c-sky\">Where frameworks require it<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Framework<\/th><th>What it expects<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a><\/td><td>Controls over removable media holding cardholder data, including handling, storage and secure destruction<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A controls<\/a> for storage media management and endpoint device protection<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a><\/td><td>Restriction of physical and logical access to data, evidenced across the observation window<\/td><\/tr>\n    <tr><td>HIPAA<\/td><td>Device and media controls, covering disposal, re-use, movement and accountability<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/td><td>Reasonable safeguards over personal data, which extends to the media it can be copied onto<\/td><\/tr>\n    <tr><td>RBI and SEBI frameworks<\/td><td>Restrictions on removable media for regulated entities, with usage logging<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The evidence request is consistent across all of them: the policy, proof it is enforced technically rather than written down, and a log showing exceptions and who approved them. A policy document with no enforcement behind it is the finding auditors write most often here.<\/p>\n\n<h2 id=\"osto\">How Osto handles device control<\/h2>\n\n<p>Device control runs from the same agent as the rest of the endpoint stack, alongside <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">antimalware and application control<\/a>, disk encryption and screen lock policy. Policy applies by device class and by user group rather than as one global setting, so the finance team and the engineering team can differ without an exception process.<\/p>\n\n<p>Because it shares a stack with everything else, the events land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the same SIEM<\/a> as identity, cloud and application activity. A blocked write attempt on its own is minor. The same user hitting it repeatedly, days after their access was reviewed, is a pattern worth seeing, and that only surfaces when endpoint and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">identity<\/a> events sit in one place. Coverage and exception reporting map into the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> evidence base without a separate export.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Close the path you cannot inspect<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Device policy by class and by group, enforced from the same agent that runs antimalware, encryption and file access controls. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Enforcement evidence built in &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is device control?<\/summary>\n  <p>An endpoint capability that governs which removable media and peripherals can connect to a managed machine and what they are permitted to do. It covers USB storage, external drives, phones in storage mode, SD cards, Bluetooth and printers, and it logs activity for audit.<\/p>\n<\/details>\n\n<details>\n  <summary>Is device control the same as blocking USB ports?<\/summary>\n  <p>No. Blocking is one of four modes. The others are read only, allow listing specific approved hardware by serial, and permitting with logging. Read only is usually the most workable position, because it permits files in while closing the path out.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between device control and DLP?<\/summary>\n  <p>Device control decides whether a device can connect and write, based on device class and user group. DLP decides whether specific data can leave, based on content and classification. Device control is blunter and faster to deploy. DLP is granular and covers network paths too.<\/p>\n<\/details>\n\n<details>\n  <summary>Do we need device control if all our data is in the cloud?<\/summary>\n  <p>Yes, because data reaches endpoints in order to be used. Exports, local downloads and cached files all sit on machines with physical ports. Cloud storage moves where data lives, not where it can be copied from.<\/p>\n<\/details>\n\n<details>\n  <summary>What evidence do auditors want for device control?<\/summary>\n  <p>The policy, proof of technical enforcement rather than a written rule, coverage across in-scope devices, and a record of exceptions with who approved them and when they were last reviewed.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">EPP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">DLP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mdm\/\">MDM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">Encryption at Rest<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Device control decides what can plug into a company machine and what happens when it does. Most teams treat it\u2026<\/p>\n","protected":false},"author":8,"featured_media":1152,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[553,555,554,552],"class_list":["post-1151","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-device-control","tag-device-control-vs-dlp","tag-removable-media-policy","tag-usb-device-control"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1151","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1151"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1151\/revisions"}],"predecessor-version":[{"id":1153,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1151\/revisions\/1153"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1152"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}