AC.L2-3.1.18Mobile Device Connection
Control connection of mobile devices.
[a]
mobile devices that process, store, or transmit CUI are identified;[b]
mobile device connections are authorized; and[c]
mobile device connections are monitored and logged.
Only MDM-enrolled mobiles; USB/debug restricted on CUI phones
Implementation
AO coverage. Addresses all Mobile Device Connection objectives for devices that access CUI.
Control connection. CUI mail/files require Intune enrollment or app-protection policy. Jailbroken/rooted devices are blocked. USB file transfer disabled on corporate CUI phones.
Maintenance. Monthly compliance review; remove stale device enrollments. New mobile OS major versions piloted before broad allow.
Accepted gap. Executives’ personal tablets used for airline entertainment are not enrolled and cannot open enclave apps (CA deny).
What the evidence looks like
- Intune enrollment / app protection policy
- Conditional Access grant for mobile CUI apps
- Noncompliant device deny test
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.