SC.L2-3.13.12Collaborative Device Control
Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.
[a]
collaborative computing devices are identified;[b]
collaborative computing devices provide indication to users of devices in use; and[c]
remote activation of collaborative computing devices is prohibited.
No remote activation of cameras or mics; visible indication required wherever CUI is discussed
Implementation
AO coverage. Addresses all three Collaborative Device Control objectives: identifying the devices, providing indication of use, and prohibiting remote activation.
Devices identified [a]. Laptop webcams and microphones, the two conference room camera/microphone bars and their room systems, USB headsets, the shop-floor intercom, and smart displays in common areas. The inventory is deliberately broad because the failure mode is an unlisted device — a personal smart speaker, for example, which policy prohibits in rooms where CUI is discussed.
Indication of use [b]. Every laptop model in the fleet has a hardware-wired activity LED that lights whenever the camera is powered; purchasing requires it. Laptops also carry a physical shutter for the deliberate-cover case. Room systems show an on-screen in-call banner plus a lit status bar visible from the doorway, so someone walking in can tell the room is live. Meeting clients display the microphone state persistently rather than only on hover, and the room's in-use state is also visible on the panel outside the door.
Remote activation prohibited [c]. Room systems have auto-answer disabled: an incoming call rings and requires a person in the room to accept. The meeting platform's remote camera and microphone control features are disabled tenant-wide, and support tooling that could enable a webcam during a remote session is blocked. Endpoint policy limits camera and microphone access to the approved conferencing and CAD-annotation applications, so a browser tab or an unapproved app cannot open the devices; permission prompts are required rather than pre-granted.
Discussion practice. Rooms used for CUI discussion have a printed reminder to confirm the participant list and to end rather than mute when the topic changes. The intercom is one-way announce with no listen-in capability.
Maintenance. Quarterly walkthrough of both rooms: attempt to place a call that auto-answers, confirm the banner and status bar appear, confirm the LED tracks the camera. Annual re-check of the tenant meeting policy after platform feature releases, which is when remote-control features tend to reappear enabled.
Accepted gap. One older USB conference microphone has no indicator of its own. It is used only with a room system whose in-call banner and status bar provide the indication, and it is not permitted as a standalone device on a laptop.
What the evidence looks like
- Collaborative computing device inventory including room systems and shared peripherals
- Room system configuration showing auto-answer disabled
- Meeting platform tenant policy with remote camera/microphone control disabled
- Endpoint policy restricting camera and microphone access to approved applications
- Quarterly room walkthrough checklist with indication and auto-answer test results
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.