Skip to content
ControlVerdict
AC.L2-3.1.19addresses
AC.L2-3.1.19Encrypt CUI on Mobile
Encrypt CUI on mobile devices and mobile computing platforms.
  • [a]

    mobile devices and mobile computing platforms that process, store, or transmit CUI are identified; and
  • [b]

    encryption is employed to protect CUI on identified mobile devices and mobile computing platforms.

View full control

Encrypt CUI containers on phones; no local unmarked copies

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Encrypt CUI on Mobile objectives.

Encryption. CUI is opened only in managed apps with encryption-at-rest for app data. Save-as to unmanaged local storage is blocked. Device-level encryption (platform) is required by compliance policy.

Maintenance. Quarterly confirm Open-in / save-as restrictions still apply after app updates.

Accepted gap. Offline maps app used in the field cannot be managed; it is banned from devices that have enclave apps installed (separate personal device).

What the evidence looks like

  • App protection policy showing encrypt / save-as restrictions
  • Device compliance requiring encryption
  • Test of blocked save to unmanaged storage

Environment

Intune-managed mobiles accessing labeled SharePoint/OneDrive.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.