AC.L2-3.1.20[b]: Prohibit the Use of Ownerless Storage Devices by Policy and Procedure

Mapped to NIST 800-171 Requirement: 3.1.20
CMMC Assessment Objective: AC.L2-3.1.20[b]

What This Objective Means
Your access control policy must explicitly state that unidentified, unassigned, or unauthorized portable storage devices may not be used within your information systems. This helps prevent accidental or malicious use of devices that fall outside of your security controls.
Your procedures must support this policy by detailing how unowned devices are:
• Identified
• Quarantined
• Reported
• Handled or disposed of

Why It Matters
Ownerless devices are a classic attack vector. They can:
• Be planted by attackers in a parking lot or lobby (USB drop attacks)
• Contain malicious payloads or credential-stealing tools
• Bypass traditional endpoint and network protections
Formal policy prohibitions help eliminate user uncertainty and establish clear security boundaries.

How to Implement It
• Update your access control policy to include a statement such as:
◦ “The use of portable storage devices without identifiable ownership is strictly prohibited.”
• Ensure supporting procedures define:
◦ What qualifies as an unowned or unauthorized device
◦ What actions should be taken when one is found or connected
◦ Reporting requirements and incident response actions
• Provide end-user training to reinforce this expectation

Evidence the Assessor Will Look For
• Policy and procedure documents containing explicit language prohibiting the use of unowned storage devices
• Device control or USB usage procedures aligned with this rule
• Training materials or security awareness content referencing the restriction
• Incident response playbooks that include steps for handling unknown devices

Common Gaps
• Policy prohibits unauthorized devices but doesn’t specify “unowned” or “unidentified”
• Procedures don’t define how to handle devices without an assigned user
• Users aren’t trained to recognize or report unowned device use

How Cuick Trac Helps
Cuick Trac supports this control by:
• Disabling or restricting the use of portable storage in secure environments
• Providing policy templates that include strict controls on portable storage usage
• Helping document procedures for device authorization, ownership tracking, and handling unknown media
• Supporting USB device detection and logging for organizations using integrated security tools
With Cuick Trac, unowned devices aren’t just discouraged—they’re blocked, monitored, and flagged by default.

Final CTA
If it’s not authorized, it doesn’t belong.
Schedule a Cuick Trac demo and enforce portable storage controls that leave no room for doubt—or unauthorized devices.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.