AC.L2-3.1.19Encrypt CUI on Mobile
Encrypt CUI on mobile devices and mobile computing platforms.
[a]
mobile devices and mobile computing platforms that process, store, or transmit CUI are identified; and[b]
encryption is employed to protect CUI on identified mobile devices and mobile computing platforms.
Encrypt CUI containers on phones; no local unmarked copies
Implementation
AO coverage. Addresses both Encrypt CUI on Mobile objectives.
Encryption. CUI is opened only in managed apps with encryption-at-rest for app data. Save-as to unmanaged local storage is blocked. Device-level encryption (platform) is required by compliance policy.
Maintenance. Quarterly confirm Open-in / save-as restrictions still apply after app updates.
Accepted gap. Offline maps app used in the field cannot be managed; it is banned from devices that have enclave apps installed (separate personal device).
What the evidence looks like
- App protection policy showing encrypt / save-as restrictions
- Device compliance requiring encryption
- Test of blocked save to unmanaged storage
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.