|
controlAC-19
Access Control for Mobile Devices (AC-19)
Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and Authorize the connection of mobile devices to organizational systems.
Security Baselines
LOWMODERATEHIGH
access-controlauthorizationleast-privilege
Why These Connect
Maps To4
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports32
These related controls work together — a change to one may affect the others.
Enhances5
These enhancements add specific capabilities or refinements to the base control.
Related Controls(25)
AC-3Access Enforcement (AC-3)
LMH
AC-4Information Flow Enforcement (AC-4)MH
AC-17Remote Access (AC-17)LMH
AC-18Wireless Access (AC-18)LMH
AC-7Unsuccessful Logon Attempts (AC-7)LMH
AC-11Device Lock (AC-11)MH
AC-20Use of External Systems (AC-20)LMH
CA-9Internal System Connections (CA-9)LMH
CM-2Baseline Configuration (CM-2)LMH
CM-6Configuration Settings (CM-6)LMH
IA-2Identification and Authentication (Organizational Users) (IA-2)LMH
IA-3Device Identification and Authentication (IA-3)MH
MP-2Media Access (MP-2)LMH
MP-4Media Storage (MP-4)MH
MP-5Media Transport (MP-5)MH
MP-7Media Use (MP-7)LMH
PL-4Rules of Behavior (PL-4)LMH
SC-7Boundary Protection (SC-7)LMH
SC-34Non-modifiable Executable Programs (SC-34)SC-43Usage Restrictions (SC-43)SI-3Malicious Code Protection (SI-3)LMH
SI-4System Monitoring (SI-4)LMH
IR-4Incident Handling (IR-4)LMH
SC-13Cryptographic Protection (SC-13)LMH
SC-28Protection of Information at Rest (SC-28)MH
Cross-Framework Mappings(4)
PR.AA-05PR.AA-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20223 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
PR.AA-05PR.AA-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Control Enhancements(5)
AC-19(1)Use of Writable and Portable Storage Devices (AC-19(1))WAC-19(2)Use of Personally Owned Portable Storage Devices (AC-19(2))WAC-19(3)Use of Portable Storage Devices with No Identifiable Owner (AC-19(3))WAC-19(4)Restrictions for Classified Information (AC-19(4))AC-19(5)Full Device or Container-based Encryption (AC-19(5))
MH