← AC-19

Restrictions for Classified Information

LOW MODERATE HIGH
1 Overlay 2 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

    1. (1)Connection of unclassified mobile devices to classified systems is prohibited;
    2. (2)Connection of unclassified mobile devices to unclassified systems requires approval from the authorizing official;
    3. (3)Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and
    4. (4)Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [security officials] , and if classified information is found, the incident handling policy is followed.
Discussion (NIST Supplemental Guidance)

None.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for AC-19(4) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. security officials responsible for the review and inspection of unclassified mobile devices and the information stored on those devices are defined;
  2. security policies restricting the connection of classified mobile devices to classified systems are defined;
  3. the use of unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information is prohibited unless specifically permitted by the authorizing official;
  4. prohibition of the connection of unclassified mobile devices to classified systems is enforced on individuals permitted by an authorizing official to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information;
  5. approval by the authorizing official for the connection of unclassified mobile devices to unclassified systems is enforced on individuals permitted to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information;
  6. prohibition of the use of internal or external modems or wireless interfaces within unclassified mobile devices is enforced on individuals permitted by an authorizing official to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information;
  7. random review and inspection of unclassified mobile devices and the information stored on those devices by <AC-19(04)_ODP[01] security officials> are enforced;
  8. following of the incident handling policy is enforced if classified information is found during a random review and inspection of unclassified mobile devices;
  9. the connection of classified mobile devices to classified systems is restricted in accordance with <AC-19(04)_ODP[02] security policies>.

Examine

[SELECT FROM: Access control policy; incident handling policy; procedures addressing access control for mobile devices; system design documentation; system configuration settings and associated documentation; evidentiary documentation for random inspections and reviews of mobile devices; system audit records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel responsible for random reviews/inspections of mobile devices; organizational personnel using mobile devices in facilities containing systems processing, storing, or transmitting classified information; organizational personnel with incident response responsibilities; system/network administrators; organizational personnel with information security responsibilities].

Test

[SELECT FROM: Mechanisms prohibiting the use of internal or external modems or wireless interfaces with mobile devices].

Overlays

Showing the OT/ICS overlay for the parent control AC-19 — see the AC-19(4) entries within each baseline below.

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (5)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (5)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for AC-19(4). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Access control policy
  • incident handling policy
  • system security plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Mechanisms prohibiting the use of internal or external modems or wireless interfaces with mobile devices

Other Records

  • procedures addressing access control for mobile devices
  • evidentiary documentation for random inspections and reviews of mobile devices
  • system audit records
  • other relevant documents or records