AC.L2-3.1.20[f]: Maintain Authorization Records That Include Device Ownership

Mapped Requirement and Assessment Objective

Mapped to NIST 800-171 requirement 3.1.20 and CMMC Level 2 assessment objective AC.L2-3.1.20[f].

What This Objective Means

This objective requires organizations to maintain authorization records for portable storage devices that clearly document device ownership.

Records must show who is responsible for each authorized device and be maintained in a reviewable format to support audit readiness and accountability.

Why Maintaining Authorization Records Matters

Without documented device ownership, investigations into lost or misused devices may stall, data loss may go unreported, and assessors may find your compliance evidence insufficient.

Clear ownership information helps link devices to individuals or roles for accountability and facilitates timely response when issues occur.

How to Implement AC 3.1.20f

Create and maintain a portable storage authorization log that includes details such as the device make and model, serial number, assigned owner (name, role, department), purpose and justification for use, authorization date and approver, and current status.

Store these records securely in an asset management system, ticketing system, or controlled spreadsheet and review and update them when devices are reassigned or decommissioned as part of your broader access control compliance processes.

Authorization Records Summary Table

Record Element Description
Device Identification Include make, model, and serial number for each authorized device.
Assigned Owner Record the name, role, and department of the authorized user.
Purpose and Justification Document why the device is authorized for use.
Authorization Date and Approver Capture when and by whom authorization was granted.
Status Track active, revoked, returned, or lost status for each device.

Evidence Assessors Commonly Expect

Assessors typically expect authorization records that clearly show device ownership and approval details. This may include exported logs, ticket system records, or inventory reports tying device identifiers to specific users.

Consistent and up-to-date records are important, as assessors may ask to see that records are reviewed periodically and maintained responsibly as part of a larger access control framework.

Common Gaps to Avoid

Common gaps include authorization records that do not include ownership details, devices in use without documentation, and decentralized tracking without oversight or periodic review.

FAQ

What does AC.L2-3.1.20f require?

It requires maintaining authorization records for portable storage devices that include clearly identified device ownership information.

Why is it important to track device ownership?

Tracking device ownership links devices to individuals or roles, helping investigations, accountability, and audit readiness when devices are lost or misused.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.