Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

AC-19 — Access Control for Mobile Devices

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

5Enhancements
0Parameters
3Baseline memberships
3Assessment methods

AC — Access Control · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and
  2. b.Authorize the connection of mobile devices to organizational systems.
Official NIST discussion

Discussion

A mobile device is a computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection; possesses local, non-removable or removable data storage; and includes a self-contained power source. Mobile device functionality may also include voice communication capabilities, on-board sensors that allow the device to capture information, and/or built-in features for synchronizing local data with remote locations. Examples include smart phones and tablets. Mobile devices are typically associated with a single individual. The processing, storage, and transmission capability of the mobile device may be comparable to or merely a subset of notebook/desktop systems, depending on the nature and intended purpose of the device. Protection and control of mobile devices is behavior or policy-based and requires users to take physical action to protect and control such devices when outside of controlled areas. Controlled areas are spaces for which organizations provide physical or procedural controls to meet the requirements established for protecting information and systems. Due to the large variety of mobile devices with different characteristics and capabilities, organizational restrictions may vary for the different classes or types of such devices. Usage restrictions and specific implementation guidance for mobile devices include configuration management, device identification and authentication, implementation of mandatory protective software, scanning devices for malicious code, updating virus protection software, scanning for critical software updates and patches, conducting primary operating system (and possibly other resident software) integrity checks, and disabling unnecessary hardware. Usage restrictions and authorization to connect may vary among organizational systems. For example, the organization may authorize the connection of mobile devices to its network and impose a set of usage restrictions, while a system owner may withhold authorization for mobile device connection to specific applications or impose additional usage restrictions before allowing mobile device connections to a system. Adequate security for mobile devices goes beyond the requirements specified in [AC-19](#ac-19) . Many safeguards for mobile devices are reflected in other controls. [AC-20](#ac-20) addresses mobile devices that are not organization-controlled.

Original Bare Metal Cyber perspective

From control text to operational evidence

Use Access Control for Mobile Devices as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity, authorization, least privilege, session boundaries, and access lifecycle governance.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • access approvals and entitlement records
  • role and group configuration exports
  • periodic access review results
  • authentication and authorization logs

Common failure patterns

  • standing privileges that outlive business need
  • shared or orphaned accounts
  • access rules implemented differently across systems
  • approvals that cannot be traced to actual permissions

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. AC-19a.
    1. AC-19a.[01]configuration requirements are established for organization-controlled mobile devices, including when such devices are outside of the controlled area;
    2. AC-19a.[02]connection requirements are established for organization-controlled mobile devices, including when such devices are outside of the controlled area;
    3. AC-19a.[03]implementation guidance is established for organization-controlled mobile devices, including when such devices are outside of the controlled area;
  2. AC-19b.the connection of mobile devices to organizational systems is authorized.

Examine

  • Access control policy
  • procedures addressing access control for mobile device usage (including restrictions)
  • configuration management plan
  • system design documentation
  • system configuration settings and associated documentation
  • authorizations for mobile device connections to organizational systems
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel using mobile devices to access organizational systems
  • system/network administrators
  • organizational personnel with information security responsibilities

Test

  • Access control capability for mobile device connections to organizational systems
  • configurations of mobile devices
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

AC-19(1) — Use of Writable and Portable Storage Devices

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

AC-19(2) — Use of Personally Owned Portable Storage Devices

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

AC-19(3) — Use of Portable Storage Devices with No Identifiable Owner

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

AC-19(4) — Restrictions for Classified Information

  1. (a)Prohibit the use of unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and
  2. (b)Enforce the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information:
    1. (1)Connection of unclassified mobile devices to classified systems is prohibited;
    2. (2)Connection of unclassified mobile devices to unclassified systems requires approval from the authorizing official;
    3. (3)Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and
    4. (4)Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [Organization-defined: security officials] , and if classified information is found, the incident handling policy is followed.
  3. (c)Restrict the connection of classified mobile devices to classified systems in accordance with [Organization-defined: security policies].
Official discussion

None.

Organization-defined parameters (2)
security officialssecurity officials responsible for the review and inspection of unclassified mobile devices and the information stored on those devices are defined;
security policiessecurity policies restricting the connection of classified mobile devices to classified systems are defined;
Assessment objectives and methods
  1. AC-19(04)(a)the use of unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information is prohibited unless specifically permitted by the authorizing official;
  2. AC-19(04)(b)
    1. AC-19(04)(b)(01)prohibition of the connection of unclassified mobile devices to classified systems is enforced on individuals permitted by an authorizing official to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information;
    2. AC-19(04)(b)(02)approval by the authorizing official for the connection of unclassified mobile devices to unclassified systems is enforced on individuals permitted to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information;
    3. AC-19(04)(b)(03)prohibition of the use of internal or external modems or wireless interfaces within unclassified mobile devices is enforced on individuals permitted by an authorizing official to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information;
    4. AC-19(04)(b)(04)
      1. AC-19(04)(b)(04)[01]random review and inspection of unclassified mobile devices and the information stored on those devices by [Organization-defined: security officials] are enforced;
      2. AC-19(04)(b)(04)[02]following of the incident handling policy is enforced if classified information is found during a random review and inspection of unclassified mobile devices;
  3. AC-19(04)(c)the connection of classified mobile devices to classified systems is restricted in accordance with [Organization-defined: security policies].

Examine

  • Access control policy
  • incident handling policy
  • procedures addressing access control for mobile devices
  • system design documentation
  • system configuration settings and associated documentation
  • evidentiary documentation for random inspections and reviews of mobile devices
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for random reviews/inspections of mobile devices
  • organizational personnel using mobile devices in facilities containing systems processing, storing, or transmitting classified information
  • organizational personnel with incident response responsibilities
  • system/network administrators
  • organizational personnel with information security responsibilities

Test

  • Mechanisms prohibiting the use of internal or external modems or wireless interfaces with mobile devices
Related controls
Official NIST control enhancement

AC-19(5) — Full Device or Container-based Encryption

ModerateHigh

Employ [Organization-defined: ac-19.05_odp.01] to protect the confidentiality and integrity of information on [Organization-defined: mobile devices].

Official discussion

Container-based encryption provides a more fine-grained approach to data and information encryption on mobile devices, including encrypting selected data structures such as files, records, or fields.

Organization-defined parameters (2)
ac-19.05_odp.01
mobile devicesmobile devices on which to employ encryption are defined;
Assessment objectives and methods

[Organization-defined: ac-19.05_odp.01] is employed to protect the confidentiality and integrity of information on [Organization-defined: mobile devices].

Examine

  • Access control policy
  • procedures addressing access control for mobile devices
  • system design documentation
  • system configuration settings and associated documentation
  • encryption mechanisms and associated configuration documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with access control responsibilities for mobile devices
  • system/network administrators
  • organizational personnel with information security responsibilities

Test

  • Encryption mechanisms protecting confidentiality and integrity of information on mobile devices
Related controls
Source record

Authoritative sources