Mapped to NIST 800-171 Requirement: 3.1.18
CMMC Assessment Objective: AC.L2-3.1.18[b]
What This Objective Means
This assessment objective ensures your organization has documented controls around mobile device usage, including:
• What devices are allowed to access CUI
• What security controls (e.g., encryption, MFA) must be in place
• Whether personally owned (BYOD) devices are permitted
• Who must approve mobile device access
This guidance must appear in both policies and enforceable procedures, forming a comprehensive mobile device management system.
Why It Matters
Without clear rules, mobile device usage can quickly spiral into:
• Inconsistent access control enforcement
• Increased risk of data loss due to unapproved or insecure endpoints
• Unintentional violations of CUI handling requirements
Formalizing your mobile access standards through a robust mobile device management approach protects CUI and sets boundaries for acceptable device usage.
How to Implement It
• Update your Access Control Policy and SOPs to include:
◦ Definitions of authorized mobile devices
◦ Security requirements (e.g., FIPS-compliant encryption, remote wipe, MDM enrollment)
◦ Restrictions on data storage, transmission, or sharing via mobile platforms
◦ Requirements for device approval, tracking, and review
• Include guidance on:
◦ Lost/stolen device reporting
◦ Usage in public/untrusted networks
◦ Separation of personal and work data (especially for BYOD)
Implementing a comprehensive enterprise mobile management strategy can further enhance your cybersecurity policy.
Evidence the Assessor Will Look For
• Policy documents specifying conditions for mobile device access to CUI
• Procedures that guide provisioning, use, and revocation of mobile device access
• References to encryption, authentication, and configuration baselines
• Acceptance forms or user agreements for mobile device use (if applicable)
Common Gaps
• Policy allows mobile device access but provides no specific requirements
• No written procedures supporting mobile device configuration or approval
• Personally owned devices accessing CUI without governance
How Cuick Trac Helps
Cuick Trac supports this control by:
• Providing policy and procedure templates that include CMMC-aligned mobile access controls
• Helping organizations enforce role-based access that limits CUI exposure on mobile devices
• Supporting mobile device inventory tracking and policy enforcement through effective mobile device management solutions
• Offering secure remote access that minimizes the need to store CUI locally
With Cuick Trac, your mobile device policy becomes more than a suggestion—it becomes a controlled, auditable process.
Final CTA
Set clear mobile access boundaries—and enforce them.
Schedule a Cuick Trac demo and make mobile access safe, structured, and compliant.