{"data":{"id":"AC-19","name":"Access Control for Mobile Devices","family":"AC","family_name":"Access Control","withdrawn":false,"description":"a. Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and\nb. Authorize the connection of mobile devices to organizational systems.","supplemental_guidance":"A mobile device is a computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection; possesses local, non-removable or removable data storage; and includes a self-contained power source. Mobile device functionality may also include voice communication capabilities, on-board sensors that allow the device to capture information, and/or built-in features for synchronizing local data with remote locations. Examples include smart phones and tablets. Mobile devices are typically associated with a single individual. The processing, storage, and transmission capability of the mobile device may be comparable to or merely a subset of notebook/desktop systems, depending on the nature and intended purpose of the device. Protection and control of mobile devices is behavior or policy-based and requires users to take physical action to protect and control such devices when outside of controlled areas. Controlled areas are spaces for which organizations provide physical or procedural controls to meet the requirements established for protecting information and systems.\n\nDue to the large variety of mobile devices with different characteristics and capabilities, organizational restrictions may vary for the different classes or types of such devices. Usage restrictions and specific implementation guidance for mobile devices include configuration management, device identification and authentication, implementation of mandatory protective software, scanning devices for malicious code, updating virus protection software, scanning for critical software updates and patches, conducting primary operating system (and possibly other resident software) integrity checks, and disabling unnecessary hardware.\n\nUsage restrictions and authorization to connect may vary among organizational systems. For example, the organization may authorize the connection of mobile devices to its network and impose a set of usage restrictions, while a system owner may withhold authorization for mobile device connection to specific applications or impose additional usage restrictions before allowing mobile device connections to a system. Adequate security for mobile devices goes beyond the requirements specified in AC-19. Many safeguards for mobile devices are reflected in other controls. AC-20 addresses mobile devices that are not organization-controlled.","enhancements":[{"id":"AC-19(01)","name":"Use of Writable and Portable Storage Devices","withdrawn":true,"incorporated_into":["MP-07"]},{"id":"AC-19(02)","name":"Use of Personally Owned Portable Storage Devices","withdrawn":true,"incorporated_into":["MP-07"]},{"id":"AC-19(03)","name":"Use of Portable Storage Devices with No Identifiable Owner","withdrawn":true,"incorporated_into":["MP-07"]},{"id":"AC-19(04)","name":"Restrictions for Classified Information","statement":"a. Prohibit the use of unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and\nb. Enforce the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information:\n1. Connection of unclassified mobile devices to classified systems is prohibited;\n2. Connection of unclassified mobile devices to unclassified systems requires approval from the authorizing official;\n3. Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and\n4. Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [Assignment: organization-defined security officials], and if classified information is found, the incident handling policy is followed.\nc. Restrict the connection of classified mobile devices to classified systems in accordance with [Assignment: organization-defined security policies].","baselines":[]},{"id":"AC-19(05)","name":"Full Device or Container-based Encryption","statement":"Employ [Selection: full-device encryption; container-based encryption] to protect the confidentiality and integrity of information on [Assignment: organization-defined mobile devices].","baselines":["moderate","high"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"AC-19","name":"Access Control for Mobile Devices","description":"a. Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and\nb. Authorize the connection of mobile devices to organizational systems.","discussion":"A mobile device is a computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection; possesses local, non-removable or removable data storage; and includes a self-contained power source. Mobile device functionality may also include voice communication capabilities, on-board sensors that allow the device to capture information, and/or built-in features for synchronizing local data with remote locations. Examples include smart phones and tablets. Mobile devices are typically associated with a single individual. The processing, storage, and transmission capability of the mobile device may be comparable to or merely a subset of notebook/desktop systems, depending on the nature and intended purpose of the device. Protection and control of mobile devices is behavior or policy-based and requires users to take physical action to protect and control such devices when outside of controlled areas. Controlled areas are spaces for which organizations provide physical or procedural controls to meet the requirements established for protecting information and systems.\n\nDue to the large variety of mobile devices with different characteristics and capabilities, organizational restrictions may vary for the different classes or types of such devices. Usage restrictions and specific implementation guidance for mobile devices include configuration management, device identification and authentication, implementation of mandatory protective software, scanning devices for malicious code, updating virus protection software, scanning for critical software updates and patches, conducting primary operating system (and possibly other resident software) integrity checks, and disabling unnecessary hardware.\n\nUsage restrictions and authorization to connect may vary among organizational systems. For example, the organization may authorize the connection of mobile devices to its network and impose a set of usage restrictions, while a system owner may withhold authorization for mobile device connection to specific applications or impose additional usage restrictions before allowing mobile device connections to a system. Adequate security for mobile devices goes beyond the requirements specified in AC-19. Many safeguards for mobile devices are reflected in other controls. AC-20 addresses mobile devices that are not organization-controlled.","related_controls":["AC-03","AC-04","AC-07","AC-11","AC-17","AC-18","AC-20","CA-09","CM-02","CM-06","IA-02","IA-03","MP-02","MP-04","MP-05","MP-07","PL-04","SC-07","SC-34","SC-43","SI-03","SI-04"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Adds text 'to include when such devices are outside of controlled areas'"}},"compliance_mappings":{"iso_27001_2022":["A.5.14","A.7.9","A.8.1"],"iso_27002_2022":["7.9","8.1"],"cobit_2019":["DSS05"],"pci_dss_v4":["1.5"],"nist_csf_2":["PR.AA-05"],"cis_controls_v8":["CIS 4.11","CIS 4.12"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(i)"],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["CON.7","ORP.4"],"anssi":["Hygiene.19","SecNumCloud.10.6"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(64)"],"gdpr":["Art.32(1)(a)","Art.32(1)(b)"],"dora":["Art.9(4)(a)","Art.9(4)(c)"],"bio2":["7.9","8.1"],"rbi_csf":["Annex1.8","Annex1.12"],"fisc":["FISC.T10"],"lgpd_bcb":[],"hkma_tme1":["TME1.8.5","TME1.10.2"],"mlps_2":["8.3"],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-6"],"cbuae":["CR-4"],"nca_ecc":["2-6"],"qatar_nia":["AC"],"sama_csf":["3.1","3.3","3.8"],"uae_ia":["T9"],"bog_cisd":["CISD-VIII"],"bom_ctrm":["3.12"],"cbe_csf":["CTO-1","CTO-7"],"cbn_csf":["Part3.2"],"sa_js2":["JS2-7.1"],"bot_cyber":["Ch2.6","Ch9.1"],"cpmi_pfmi":["CG.PR"],"ecb_croe":["CROE.2.3.5"],"ffiec_is":["II.C.15(c)"],"nydfs_500":["500.7"],"sebi_cscrf":["PR.ES"],"cmmc_2":["AC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.7.3"],"fda_21_cfr_11":["§11.10(h)"],"fda_cyber":[],"hitrust_csf":["01.b","01.d","05.c"],"iso_27799":["6.3","11.2"],"lloyds_ms":["MS8.3"],"naic_ds":["4-access"],"nhs_dspt":["NDG-9.7"],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.6"],"owasp_masvs_v2":[],"csa_ccm_v4":["UEM-01","UEM-13"],"csa_aicm":["UEM-01","UEM-13"],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1040","name":"Network Sniffing","tactics":["credential-access","discovery"],"mapping_type":"mitigates","mapping_rationale":"Mobile device access controls—including VPN enforcement and network-access restrictions—mitigate network sniffing on portable devices by ensuring communications traverse encrypted channels, preventing credential interception on untrusted networks."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Access controls for mobile devices restrict email collection by enforcing device authorization, containerization, and data-protection policies that prevent unauthorized email access from unmanaged or compromised portable devices."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Mobile device management policies restrict automated collection by controlling which applications can access organizational data on portable devices, preventing unauthorized data-harvesting software from operating on managed devices."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Access controls for portable devices restrict cloud storage access by enforcing device compliance requirements and conditional-access policies that prevent data collection from unauthorized or non-compliant mobile devices."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Mobile device access controls protect credentials by enforcing device encryption, secure-container policies, and remote-wipe capabilities that prevent unsecured credential exposure on lost, stolen, or compromised devices."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Portable device access controls mitigate adversary-in-the-middle attacks by enforcing VPN usage, certificate validation, and network-trust policies that prevent MITM interception on untrusted wireless networks."},{"id":"T1558","name":"Steal or Forge Kerberos Tickets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Mobile device access controls restrict Kerberos ticket exposure by enforcing device compliance and limiting which portable devices can participate in Kerberos authentication, reducing ticket-theft opportunities."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Access controls for portable devices protect data integrity by enforcing device security policies, application allowlisting, and containerization that prevent unauthorized data modification from compromised mobile devices."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Mobile device access controls restrict configuration data access by enforcing device authorization for management-protocol connections, preventing unauthorized network device management from portable devices."},{"id":"T1020.001","name":"Traffic Duplication","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Portable device access controls mitigate traffic duplication by restricting network-monitoring capabilities on mobile devices, preventing adversaries from using compromised portable devices to mirror network traffic."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Mobile device management enables detection of Windows event log clearing on portable devices by enforcing logging policies and centralized log forwarding that preserves evidence even if local logs are deleted."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Access controls for portable devices enable detection of Unix/Mac log clearing through centralized log forwarding and device-compliance monitoring that identifies tampering with local audit records."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Mobile device access controls protect mailbox data integrity by enforcing device-level security policies that prevent unauthorized email deletion and enable centralized mailbox-audit logging."},{"id":"T1114.001","name":"Local Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Portable device access controls restrict local email collection by enforcing email containerization and data-protection policies that prevent bulk email extraction from managed mobile devices."},{"id":"T1114.002","name":"Remote Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Mobile device management restricts remote email collection by enforcing device-compliance requirements for email-protocol access, preventing unauthorized portable devices from connecting to mail servers."},{"id":"T1114.003","name":"Email Forwarding Rule","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Access controls for mobile devices restrict email forwarding-rule creation by enforcing policies that prevent unauthorized mail-rule modifications from portable devices connecting to organizational email."},{"id":"T1550.001","name":"Application Access Token","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Portable device access controls restrict application-token usage by enforcing device-compliance requirements that prevent stolen application access tokens from being used on unauthorized mobile devices."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Mobile device encryption and access controls protect private keys stored on portable devices by enforcing device-level encryption, biometric authentication, and secure-enclave storage for cryptographic material."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Access controls for portable devices mitigate ARP poisoning by enforcing VPN and trusted-network policies that encrypt communications from mobile devices on potentially hostile local networks."},{"id":"T1557.004","name":"Evil Twin","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Portable device access controls mitigate evil twin attacks by enforcing certificate-based network authentication, VPN-always-on policies, and wireless-network trust validation on managed mobile devices."},{"id":"T1558.002","name":"Silver Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Mobile device access controls limit silver ticket exploitation by enforcing device compliance for service access, adding an additional verification layer beyond Kerberos ticket presentation."},{"id":"T1558.003","name":"Kerberoasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Access controls for portable devices limit kerberoasting risk by restricting which devices can request service tickets, reducing the attack surface for offline password cracking from unmanaged endpoints."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Portable device management reduces AS-REP roasting risk by enforcing pre-authentication requirements on device-level connections and limiting which devices can initiate Kerberos authentication exchanges."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Mobile device access controls protect stored data from manipulation by enforcing device encryption, application sandboxing, and integrity verification that prevent unauthorized modifications to organizational data on portable devices."},{"id":"T1565.002","name":"Transmitted Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Access controls for portable devices protect data in transit from manipulation by enforcing VPN, TLS, and certificate-pinning policies that prevent adversary modification of communications from mobile devices."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Portable device access controls restrict SNMP access by preventing unauthorized management-protocol connections from mobile devices, requiring device compliance before network device management is permitted."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Mobile device management restricts network device configuration access by enforcing device-authorization policies that prevent configuration extraction from unauthorized portable devices."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.5.14, A.7.9 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.AA-05 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-006","SP-007","SP-015","SP-026","SP-052"]}}