3.1.21[c]

  • Determination Statement

    Use of organizational portable storage devices containing CUI on external systems is limited as defined.

  • Requirement

    Limit use of portable storage devices on external systems.

  • Requirement Discussion

    Limits on the use of organization-controlled portable storage devices in external systems include complete prohibition of the use of such devices or restrictions on how the devices may be used and under what conditions the devices may be used. Note that while “external” typically refers to outside of the organization’s direct supervision and authority, that is not always the case. Regarding the protection of CUI across an organization, the organization may have systems that process CUI and others that do not. Among the systems that process CUI there are likely access restrictions for CUI that apply between systems. Therefore, from the perspective of a given system, other systems within the organization may be considered “external" to that system.

More Info

  • Family

    Access Control
  • DoD Scoring Methodology Points

    1

  • Related NIST 800-171 ID

  • Related CMMC ID

  • Related NIST 800-53 ID

    AC-20(2)

  • Reference Documents

    • N/A

NIST 800-171A Assessment Guidance

CMMC Training

Our CMMC Overview Course simplifies CMMC. Enroll so you can make informed decisions!