# SC-41 Port and I/O Device Access

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: [Selection (one): Physically; Logically] disable or remove [Assignment: organization-defined connection ports or input/output devices] on the following systems or system components: [Assignment: organization-defined systems or system components].
Guidance: Connection ports include Universal Serial Bus (USB), Thunderbolt, and Firewire (IEEE 1394). Input/output (I/O) devices include compact disc and digital versatile disc drives. Disabling or removing such connection ports and I/O devices helps prevent the exfiltration of information from systems and the introduction of malicious code from those ports or devices. Physically disabling or removing ports and/or devices is the stronger action.

## Clauses by framework (18 frameworks)
- iso_27002_2022: 8.1
- cobit_2019: DSS05
- mas_trm: 11
- bsi_grundschutz: NET.3.1
- osfi_b13: B-13.3.2
- bio2: 8.1
- rbi_csf: Annex1.4
- hkma_tme1: TME1.11.1, TME1.11.3
- cra: CRA.I.2j
- cbb_tm: TM-8
- cbuae: CR-7
- sama_csf: 3.3
- bog_cisd: CISD-VI
- cbe_csf: CTO-6, CTO-7
- cbn_csf: Part3.3
- sa_js2: JS2-7.2, JS2-8.4
- bot_cyber: Ch2.6
- sebi_cscrf: PR.ES

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-41
- Clauses only: /api/v1/controls/SC-41?fields=mappings
- Page for people: /controls/sc-41/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
