1. Choose Activity policy item in the context menu.

2. Switch to Common rules tab in the Application control policy window. Select the Devices protection scope from the drop-down list.

3. Select the USB Devices from the list and uncheck the
• Uncheck the Read checkbox in order to protect the selected USB device from reading by applications. This will automatically block changing and deletion of the files and folders stores on the USB device.
• Uncheck Write checkbox to protect the selected the selected USB device from new files and folders creation and altering existing data by applications.
• Uncheck the Delete checkbox to protect files and folders stored on the selected USB device from being deleted.
4. Click on Additional link.

5. Change following settings in the Additional window:
| • | Users – select the users to be controlled by the rule |

| • | Time – set time periods for the rule to be active. The rule will be active at all times by default |

| • | Exceptions – select the devices to be excluded from the rule. You can additionally allow/deny Read, Write and Delete access for the excepted device. |
| • | Update – update the listed of USB devices attached to computer |
| • | Remove - remove the selected USB device from the list of excepted devices |
6. Click on OK button in the Additional window to save changes

7. Click on OK or Apply button in the Common rules tab to save new rule and to update Application control policy.

|