CMMC MP.3.123 - Prohibit Portable Storage Devices with no Identifiable Owner

CMMC MP.3.123 - Prohibit Portable Storage Devices with no Identifiable Owner

Requirement text: MP.3.123: Prohibit the use of portable storage devices when such devices have no
identifiable owner.

DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2
Requiring identifiable owners (e.g., individuals, organizations, or projects) for portable
storage devices reduces the overall risk of using such technologies by allowing organizations
to assign responsibility and accountability for addressing known vulnerabilities in the
devices (e.g., insertion of malicious code).

CMMC CLARIFICATION
A portable storage device is a small hard drive or solid state device that is designed to hold
various types of data. It typically plugs into a laptop or desktop port (e.g., USB port). Due to
the small size of the device they can be easily lost. This makes the portable storage device
an attractive tool to hack an organization. Since the device can hold any type of file it could
contain an executable or document that a staff member opens to determine who owns the
portable storage device Therefore, an organization should prohibit use if it cannot trace the
device to an owner.

Example
You are the IT manager for your organization. As you enter the building a staff member says
they found a USB drive in the parking lot. You ask if the USB device indicates who might be
the owner. The staff member responds that there didn’t appear to be any special markings
on the drive. Once they get to their office they plan to plug the drive into their laptop to see
what type of files are on the drive. The data might indicate which project owns it. You
remind them that IT policies and practices expressly prohibit plugging unknown devices into
computers. You remind the staff member that your organization’s IT policy directs them to
turn in the lost USB device to the IT Helpdesk so they can resolve the issue.

References
• NIST SP 800-171 Rev 1 3.8.8
• NIST CSF v1.1 PR.PT-2
• CERT RMM v1.2 MON:SG2.SP4
• NIST SP 800-53 Rev 4 MP-7(1)
    • Related Articles

    • CMMC AC.2.006 - Limit Storage Devices

      Requirement text: AC.2.006: Limit use of portable storage devices on external systems. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2  Limits on the use of organization-controlled portable storage devices in external systems include complete ...
    • Media Protection: SP 800-171 Security Family 3.8

      Media protection is a requirement that addresses the defense of system media, which can be described as both digital and non-digital. Examples of digital media include: diskettes, magnetic tapes, external/removable hard disk drives, flash drives, ...
    • CMMC MP.2.121 - Control Use of Removable Media

      Requirement text: MP.2.121: Control the use of removable media on system components. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 In contrast to requirement MP.2.119, which restricts user access to media, this requirement restricts the use of ...
    • CMMC MP.3.125 - Encrypt CUI on Digital Media

      Requirement text: MP.3.125: Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 ...
    • CMMC SC.2.178 - Prohibit and Monitor Remote Activation of Collaborative Computing Devices

      Requirement text: SC.2.178: Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 Collaborative computing devices ...