Access Control for Mobile Devices
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of AC-19 — Access Control for Mobile Devices. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of AC-19 — Access Control for Mobile Devices. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
A mobile device is a computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection; possesses local, non-removable or removable data storage; and includes a self-contained power source. Mobile device functionality may also include voice communication capabilities, on-board sensors that allow the device to capture information, and/or built-in features for synchronizing local data with remote locations. Examples include smart phones and tablets. Mobile devices are typically associated with a single individual. The processing, storage, and transmission capability of the mobile device may be comparable to or merely a subset of notebook/desktop systems, depending on the nature and intended purpose of the device. Protection and control of mobile devices is behavior or policy-based and requires users to take physical action to protect and control such devices when outside of controlled areas. Controlled areas are spaces for which organizations provide physical or procedural controls to meet the requirements established for protecting information and systems. Due to the large variety of mobile devices with different characteristics and capabilities, organizational restrictions may vary for the different classes or types of such devices. Usage restrictions and specific implementation guidance for mobile devices include configuration management, device identification and authentication, implementation of mandatory protective software, scanning devices for malicious code, updating virus protection software, scanning for critical software updates and patches, conducting primary operating system (and possibly other resident software) integrity checks, and disabling unnecessary hardware. Usage restrictions and authorization to connect may vary among organizational systems. For example, the organization may authorize the connection of mobile devices to its network and impose a set of usage restrictions, while a system owner may withhold authorization for mobile device connection to specific applications or impose additional usage restrictions before allowing mobile device connections to a system. Adequate security for mobile devices goes beyond the requirements specified in AC-19 . Many safeguards for mobile devices are reflected in other controls. AC-20 addresses mobile devices that are not organization-controlled.
Enhancements NIST SOURCE
AC-19(1) Use of Writable and Portable Storage Devices WITHDRAWN
Withdrawn. Incorporated into MP-7.
AC-19(2) Use of Personally Owned Portable Storage Devices WITHDRAWN
Withdrawn. Incorporated into MP-7.
AC-19(3) Use of Portable Storage Devices with No Identifiable Owner WITHDRAWN
Withdrawn. Incorporated into MP-7.
AC-19(4) Restrictions for Classified Information LOW MODERATE HIGH
- (a) Prohibit the use of unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and
- (b) Enforce the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information:
- (1) Connection of unclassified mobile devices to classified systems is prohibited;
- (2) Connection of unclassified mobile devices to unclassified systems requires approval from the authorizing official;
- (3) Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and
- (4) Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [security officials] , and if classified information is found, the incident handling policy is followed.
- (c) Restrict the connection of classified mobile devices to classified systems in accordance with [security policies].
Discussion
None.
AC-19(5) Full Device or Container-based Encryption LOW ✓ MODERATE ✓ HIGH
Employ [one of: full-device encryption; container-based encryption] to protect the confidentiality and integrity of information on [mobile devices].
Discussion
Container-based encryption provides a more fine-grained approach to data and information encryption on mobile devices, including encrypting selected data structures such as files, records, or fields.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for AC-19 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- configuration requirements are established for organization-controlled mobile devices, including when such devices are outside of the controlled area;
- connection requirements are established for organization-controlled mobile devices, including when such devices are outside of the controlled area;
- implementation guidance is established for organization-controlled mobile devices, including when such devices are outside of the controlled area;
- the connection of mobile devices to organizational systems is authorized.
Examine
[SELECT FROM: Access control policy; procedures addressing access control for mobile device usage (including restrictions); configuration management plan; system design documentation; system configuration settings and associated documentation; authorizations for mobile device connections to organizational systems; system audit records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel using mobile devices to access organizational systems; system/network administrators; organizational personnel with information security responsibilities].
Test
[SELECT FROM: Access control capability for mobile device connections to organizational systems; configurations of mobile devices].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for AC-19. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Access control policy
- system security plan
Configuration
- configuration management plan
- system design documentation
- system configuration settings and associated documentation
Testing
- Access control capability for mobile device connections to organizational systems
- configurations of mobile devices
Other Records
- procedures addressing access control for mobile device usage (including restrictions)
- authorizations for mobile device connections to organizational systems
- system audit records
- other relevant documents or records