Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.1.18OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.1.18Mobile device connection control

3.1 Access Control · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Independent interpretation

What this requirement is after

Phones and tablets connect on your terms. A device that syncs company email or opens CUI attachments is inside the boundary whether or not you bought it, so connection is conditioned on enrollment and a minimum security posture rather than left open.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Decide the mobile stance first — corporate devices only, or personal devices under management — and write it down; every technical setting follows from that choice.
  • Enforce with device management and conditional access: unenrolled devices, or devices failing the posture check, simply do not reach mail and files that may carry CUI.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The mobile device policy and the enrollment register
  • Conditional access or equivalent configuration blocking unmanaged devices
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated