Portable Storage Use
Practice statement
Limit use of portable storage devices on external systems.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.21.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(3)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
the use of portable storage devices containing CUI on external systems is identified and documented;
1 example covers this
- [b]
limits on the use of portable storage devices containing CUI on external systems are defined; and
1 example covers this
- [c]
the use of portable storage devices containing CUI on external systems is limited as defined.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
AC.L2-3.1.21Portable Storage Use
Limit use of portable storage devices on external systems.
[a]
the use of portable storage devices containing CUI on external systems is identified and documented;[b]
limits on the use of portable storage devices containing CUI on external systems are defined; and[c]
the use of portable storage devices containing CUI on external systems is limited as defined.
No org USB on home PCs; portable media only on managed endpoints
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses all Portable Storage Use objectives regarding external systems.
Limit. Portable storage that may hold CUI is org-issued, hardware-encrypted, and only mountable on managed enclave endpoints. Policy prohibits using those drives on home/personal PCs or hotel business centers.
External systems. Staff acknowledge that CUI portable media is not connected to unmanaged external systems. Spot checks via MDM device reports and random interviews.
Maintenance. Exception tickets time-bound (≤30 days). Lost-media process mirrors sanitization SOP.
Accepted gap. A supplier still requires DVD drop-ship. Disc is encrypted archive; burned only on a dedicated air-gapped burner host; courier chain-of-custody logged.
What the evidence looks like
- MDM USB policy
- Issued encrypted-media inventory
- User acknowledgment / training record
- DVD exception chain-of-custody sample
Environment
Hybrid work; USB write blocked on enclave devices.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.