← Controls / AC

AC-19 Access Control for Mobile Devices

Access Control

Low Moderate High

Description

a. Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and b. Authorize the connection of mobile devices to organizational systems.

Supplemental Guidance

A mobile device is a computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection; possesses local, non-removable or removable data storage; and includes a self-contained power source. Mobile device functionality may also include voice communication capabilities, on-board sensors that allow the device to capture information, and/or built-in features for synchronizing local data with remote locations. Examples include smart phones and tablets. Mobile devices are typically associated with a single individual. The processing, storage, and transmission capability of the mobile device may be comparable to or merely a subset of notebook/desktop systems, depending on the nature and intended purpose of the device. Protection and control of mobile devices is behavior or policy-based and requires users to take physical action to protect and control such devices when outside of controlled areas. Controlled areas are spaces for which organizations provide physical or procedural controls to meet the requirements established for protecting information and systems. Due to the large variety of mobile devices with different characteristics and capabilities, organizational restrictions may vary for the different classes or types of such devices. Usage restrictions and specific implementation guidance for mobile devices include configuration management, device identification and authentication, implementation of mandatory protective software, scanning devices for malicious code, updating virus protection software, scanning for critical software updates and patches, conducting primary operating system (and possibly other resident software) integrity checks, and disabling unnecessary hardware. Usage restrictions and authorization to connect may vary among organizational systems. For example, the organization may authorize the connection of mobile devices to its network and impose a set of usage restrictions, while a system owner may withhold authorization for mobile device connection to specific applications or impose additional usage restrictions before allowing mobile device connections to a system. Adequate security for mobile devices goes beyond the requirements specified in AC-19. Many safeguards for mobile devices are reflected in other controls. AC-20 addresses mobile devices that are not organization-controlled.

Changes from Rev 4

Adds text 'to include when such devices are outside of controlled areas'

Enhancements (2)

What NIST adds to this control. Select one to read its statement.

AC-19(04) Restrictions for Classified Information

a. Prohibit the use of unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and b. Enforce the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information: 1. Connection of unclassified mobile devices to classified systems is prohibited; 2. Connection of unclassified mobile devices to unclassified systems requires approval from the authorizing official; 3. Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and 4. Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [Assignment: organization-defined security officials], and if classified information is found, the incident handling policy is followed. c. Restrict the connection of classified mobile devices to classified systems in accordance with [Assignment: organization-defined security policies].

AC-19(05) Full Device or Container-based Encryption ModerateHigh

Employ [Selection: full-device encryption; container-based encryption] to protect the confidentiality and integrity of information on [Assignment: organization-defined mobile devices].

Withdrawn by NIST:

  • AC-19(01) Use of Writable and Portable Storage Devices, now in MP-07
  • AC-19(02) Use of Personally Owned Portable Storage Devices, now in MP-07
  • AC-19(03) Use of Portable Storage Devices with No Identifiable Owner, now in MP-07

Compliance Mappings

ISO 27001:2022

A.5.14A.7.9A.8.1

ISO 27002:2022

7.98.1

COBIT 2019

DSS05

CIS Controls v8

CIS 4.11CIS 4.12

NIST CSF 2.0

PR.AA-05

PCI DSS v4.0.1

1.5

CSA CCM v4

UEM-01UEM-13

CSA AICM v1

UEM-01UEM-13

NIS2 Directive

Art. 21(2)(i)

MAS TRM

9

BSI IT-Grundschutz

CON.7ORP.4

ANSSI

Hygiene.19SecNumCloud.10.6

FINMA Circular 2023/1

IV.B.d(59)IV.C(64)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(a)Art.32(1)(b)

EU DORA

Art.9(4)(a)Art.9(4)(c)

BIO2

7.98.1

RBI CSF

Annex1.8Annex1.12

FISC Security Guidelines

FISC.T10

HKMA TM-E-1

TME1.8.5TME1.10.2

MLPS 2.0

8.3

SAMA CSF

3.13.33.8

NCA ECC

2-6

UAE IA

T9

CBB TM

TM-6

Qatar NIA

AC

CBUAE

CR-4

CBE CSF

CTO-1CTO-7

SA JS2

JS2-7.1

CBN CSF

Part3.2

BoG CISD

CISD-VIII

BoM CTRM

3.12

CPMI-IOSCO PFMI

CG.PR

FFIEC IS

II.C.15(c)

NYDFS 500

500.7

ECB CROE

CROE.2.3.5

SEBI CSCRF

PR.ES

BOT Cyber Resilience

Ch2.6Ch9.1

CMMC 2.0

AC

Solvency II

EIOPA-ICT-4.6

Lloyd's Minimum Standards

MS8.3

NAIC Insurance Data Security

4-access

FCA SYSC 13

SYSC 13.7.3

HITRUST CSF v11

01.b01.d05.c

FDA 21 CFR Part 11

§11.10(h)

ISO 27799

6.311.2

NHS DSPT

NDG-9.7

ISO 17799 (legacy)

11.7.1

COBIT 4.1 (legacy)

None.