This control requires your organization to explicitly prohibit the use of any portable storage device (e.g., USB drives, SD cards, external hard drives) if the device’s owner cannot be clearly identified. This is a protective measure to reduce the risk of introducing malware or unauthorized access to Controlled Unclassified Information (CUI) systems.