CIS IG1 Control 10.3: The Parking-Lot USB Still Works

Disable Autorun and Autoplay for Removable Media

 

One of the oldest tricks in security still works. Leave a few USB drives in a parking lot, a lobby, or a break room, and wait. Someone picks one up, plugs it into a work computer to see what’s on it, and if that computer is set to automatically run whatever the drive offers, the attacker just skipped past nearly every other defense you have. Control 10.3 closes that specific door by turning off the feature that lets removable media run on its own.

What makes this one worth a leader’s attention isn’t complexity. It’s how cheap the fix is compared to what it prevents. This is a configuration change, not a purchase, and it removes an entire category of attack that relies on nothing more than human curiosity.

 

What this control actually says (in plain English)

 

Here’s the translation: stop your computers from automatically opening or running whatever is on a USB drive, memory card, or disc the moment it’s plugged in.

Now the official version. Control 10.3 says you should disable autorun and autoplay auto-execute functionality for removable media.

Autorun and autoplay were built for convenience, so a disc or drive could launch on its own. That same convenience is exactly what an attacker borrows to get their code running without anyone choosing to open anything.

 

Why business leaders should care

 

The vulnerability this control addresses isn’t really technical. It’s human. People are naturally curious, and a found USB drive is almost designed to be plugged in, whether to find its owner or just to see what’s on it. Security awareness training helps, but curiosity is persistent, and it only takes one person on one machine. Disabling auto-execute means that even when someone does plug in an unknown device, nothing runs on its own. The curiosity is still there, but the automatic consequence is gone.

This is secure configuration in its simplest, most concrete form. When I wrote about it in Secure by Design, Not by Accident, the theme was that devices arrive configured for convenience rather than safety, and that closing those gaps is a deliberate decision you make and enforce. Autorun is a textbook example. It ships enabled or half-enabled for ease of use, it serves almost no real purpose in a modern business, and turning it off is close to pure upside.

 

What “good” looks like

 

This is one of the most decisive cost-to-benefit trades in all of IG1. Here’s the practical path.

  • Disable autorun and autoplay across the fleet. Turn the feature off for removable media on every machine, using group policy or your endpoint management platform so it’s applied consistently.
  • Enforce it centrally, not per user. Push the setting from a central standard rather than relying on individuals, so it can’t be casually turned back on and so new machines inherit it automatically.
  • Consider going further for higher-risk roles. For sensitive systems or roles, think about restricting removable media more tightly, or blocking it outright where it isn’t needed.
  • Let anti-malware back it up. Pair this with the protection from your anti-malware controls so that media which is opened deliberately still gets scanned before anything runs.

 

The audit and defensibility angle

 

This is a small control that shows real discipline. Being able to demonstrate that autorun and autoplay are disabled by policy across every machine tells an auditor or an insurer that you’ve thought about the mundane, human ways attacks actually start, not just the sophisticated ones. It’s the kind of low-cost, centrally enforced hardening that signals an environment managed on purpose rather than left at its defaults.

The dropped-USB trick endures because it’s cheap for the attacker and it exploits something you can’t patch: curiosity. You can’t stop people from being curious, but you can make sure their curiosity doesn’t automatically run someone else’s code. Disabling autorun and autoplay is a one-time, centrally enforced decision with almost no downside, and it quietly retires one of the oldest ways in the book.

Heath Gieson

Heath Gieson

Let's Connect. Make Better Technology Decisions with Forthright.

Understand your current environment and get a clear path forward. Let's connect.

who we support

Built for organizations that prioritize security, uptime, and compliance.

Z

Teams that want executive-level technology guidance and strategy for growth

Z

Operations that cannot afford disruption from unreliable or reactive IT

Z

Organizations ready to modernize operations with AI, automation, and data-driven insights

Z

Organizations handling sensitive data that need to stay secure and compliant without slowing down operations

Z

Organizations seeking outsourced IT support that strengthens their internal team or provides complete coverage when no internal team is in place

Forthright is the technology partner you should be working with

2024_CRN_MSP_500
Certified minority business
comptia-cybersecurity-trustmark