Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.01.18OFFICIAL TITLEPENDING NIST SME REVIEW

03.01.18Access Control for Mobile Devices

03.01 Access Control · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires establishing usage restrictions, configuration requirements, and connection requirements for mobile devices; authorizing the connection of mobile devices to the system; and implementing full-device or container-based encryption to protect the confidentiality of CUI on mobile devices (aligned to SP 800-53 AC-19 with the CUI-encryption enhancement).

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Phones and tablets touch CUI only on your terms: enrolled or containerized, configured to written rules, and encrypted — the whole device or a managed work container. For most small contractors the honest options are two: corporate-enrolled devices with enforced encryption, or app-protection containers around mail and files on personal phones. Unmanaged company mail on a personal phone is the standing violation.

Across revisions

Merges Rev. 2's mobile connection control (3.1.18) and CUI encryption on mobile devices (3.1.19); the encryption duty survives intact as an explicit element, with full-device and container-based encryption both recognized.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Decide the model — corporate-owned enrolled devices, personal devices with a managed container, or no mobile CUI at all — and write it down.
  • Enforce encryption and passcode requirements technically through MDM or app-protection policy, not through an acceptable-use memo alone.
  • Bound what the container can do: cut copy-paste and save-to-personal-storage paths out of the CUI applications.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The mobile-device standard with usage restrictions and the authorization model
  • MDM or app-protection policy exports showing encryption enforced
  • Enrollment reports showing the devices with CUI access under management
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated