Mapped Requirement and Assessment Objective
Mapped to NIST 800-171 requirement 3.1.20 and CMMC Level 2 assessment objective AC.L2-3.1.20[f].
What This Objective Means
This objective requires organizations to maintain authorization records for portable storage devices that clearly document device ownership.
Records must show who is responsible for each authorized device and be maintained in a reviewable format to support audit readiness and accountability.
Why Maintaining Authorization Records Matters
Without documented device ownership, investigations into lost or misused devices may stall, data loss may go unreported, and assessors may find your compliance evidence insufficient.
Clear ownership information helps link devices to individuals or roles for accountability and facilitates timely response when issues occur.
How to Implement AC 3.1.20f
Create and maintain a portable storage authorization log that includes details such as the device make and model, serial number, assigned owner (name, role, department), purpose and justification for use, authorization date and approver, and current status.
Store these records securely in an asset management system, ticketing system, or controlled spreadsheet and review and update them when devices are reassigned or decommissioned as part of your broader access control compliance processes.
Authorization Records Summary Table
| Record Element | Description |
|---|---|
| Device Identification | Include make, model, and serial number for each authorized device. |
| Assigned Owner | Record the name, role, and department of the authorized user. |
| Purpose and Justification | Document why the device is authorized for use. |
| Authorization Date and Approver | Capture when and by whom authorization was granted. |
| Status | Track active, revoked, returned, or lost status for each device. |
Evidence Assessors Commonly Expect
Assessors typically expect authorization records that clearly show device ownership and approval details. This may include exported logs, ticket system records, or inventory reports tying device identifiers to specific users.
Consistent and up-to-date records are important, as assessors may ask to see that records are reviewed periodically and maintained responsibly as part of a larger access control framework.
Common Gaps to Avoid
Common gaps include authorization records that do not include ownership details, devices in use without documentation, and decentralized tracking without oversight or periodic review.
FAQ
What does AC.L2-3.1.20f require?
It requires maintaining authorization records for portable storage devices that include clearly identified device ownership information.
Why is it important to track device ownership?
Tracking device ownership links devices to individuals or roles, helping investigations, accountability, and audit readiness when devices are lost or misused.