Number | Title | Impact | Priority | Subject Area |
---|---|---|---|---|
SC-41 | Port And I/o Device Access | P0 | System And Communications Protection |
Instructions |
---|
The organization physically disables or removes Assignment: organization-defined connection ports or input/output devices on Assignment: organization-defined information systems or information system components. |
Guidance |
---|
Connection ports include, for example, Universal Serial Bus (USB) and Firewire (IEEE 1394). Input/output (I/O) devices include, for example, Compact Disk (CD) and Digital Video Disk (DVD) drives. Physically disabling or removing such connection ports and I/O devices helps prevent exfiltration of information from information systems and the introduction of malicious code into systems from those ports/devices. |
Enhancements |
---|