Device Control: USB and peripheral governance
Device Control in Dual-Strike XISEM tracks removable media and peripheral usage on managed endpoints: USB storage, Bluetooth classes, and policy-defined device types. Evidence flows from the XISEM Agent harvest — platform layer interprets and maps to detections and compliance controls.
Route: Settings → Device Control · Support wiki → Device control
Why MSPs enable it
• Healthcare — HIPAA media controls
• Finance — PCI removable media
• Legal — Exfil prevention narrative
• Industrial — OT/air-gap hybrid sites
Policy model (conceptual)
• Allow list — encrypted corporate USB IDs only
• Read-only — mount but block write
• Block — mass storage class blocked; log attempt
• Audit-only — no block, full evidence for COBRA²
Policies deploy via agent configuration — not a separate agent.
Correlation value
Device Control alone is a log. With correlation:
• USB write attempt + browsing upload to personal cloud → COBRA exfil rule
• Blocked device + Entra sign-in from same user → Investigation seed
• Repeated violations → ASPIRE Security pillar impact
Rollout advice
1. Start audit-only two weeks — show client evidence
2. Agree allow list with IT (corporate encrypted keys)
3. Switch to block for mass storage class
4. Document exceptions per department in client org notes
Compliance mapping
Maps to NIST MP family, CIS Control 10, CMMC MP.LO practices — evidence export via Compliance module.
Related: COBRA² guide · Investigations workflow · FIM preview (8.8)
Agent: dual-strike.com/downloads 8.7.0.17 GA
Device identifiers in console are hashed — do not publish raw hardware IDs externally.


