The purpose of this policy is to establish an authorized method for controlling storage devices that contain or access information resources at Ripple Treasury.
Write access via portable devices (CD’s, USB drives, etc.) is disabled via group policy. Exceptions may be made for specific servers or users with the approval of the Security & Compliance team. Removable media permissions are reviewed on a quarterly basis as a part of the access review process.
Storage devices include, but are not limited to: Universal Serial Bus (USB) devices, Compact Discs (CDs), Digital Versatile Discs (DVDs), flash drives, and any other existing or future storage device, either personally owned or Ripple Treasury owned, that may connect to or access the information systems at Ripple Treasury.
Client databases shall not be written to removable media without the approval of the Security & Compliance team.
All work-related information/files should be stored on Ripple Treasury servers.
Ripple Treasury owned/managed devices that contain sensitive information (including any cell phone with company email, company owned laptop, external hard drive or removable media) are properly wiped of any confidential data prior to disposal.
All relevant storage media (hard drives, external media) are maintained until properly disposed of with an Electronics Recycling facility or through physical destruction, upon which a certificate of destruction is obtained (if available).
Copyright 2025 Ripple Labs Inc.
