Skip to content
ControlVerdict
AC.L2-3.1.18CMMC Level 2Level 2

Mobile Device Connection

Practice statement

Control connection of mobile devices.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.18.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(3)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    mobile devices that process, store, or transmit CUI are identified;

    1 example covers this

  2. [b]

    mobile device connections are authorized; and

    1 example covers this

  3. [c]

    mobile device connections are monitored and logged.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AC.L2-3.1.18Mobile Device Connection
    Control connection of mobile devices.
    • [a]

      mobile devices that process, store, or transmit CUI are identified;
    • [b]

      mobile device connections are authorized; and
    • [c]

      mobile device connections are monitored and logged.

    Only MDM-enrolled mobiles; USB/debug restricted on CUI phones

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses all Mobile Device Connection objectives for devices that access CUI.

    Control connection. CUI mail/files require Intune enrollment or app-protection policy. Jailbroken/rooted devices are blocked. USB file transfer disabled on corporate CUI phones.

    Maintenance. Monthly compliance review; remove stale device enrollments. New mobile OS major versions piloted before broad allow.

    Accepted gap. Executives’ personal tablets used for airline entertainment are not enrolled and cannot open enclave apps (CA deny).

    What the evidence looks like

    • Intune enrollment / app protection policy
    • Conditional Access grant for mobile CUI apps
    • Noncompliant device deny test

    Environment

    BYOD + a few corporate phones; Intune App Protection / enrollment.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.