Beyond CMMC Level 1
The free web app covers the 17 CMMC Level 1 practices. This requirement is part of the full NIST 800-171 set — get the desktop app to work on all 110 requirements with SPRS scoring. Previously saved data is shown read-only below, and your data always remains exportable in full.
Get the desktop appSecurity Requirements for 03.01.19 Encrypt CUI on Mobile
Organizations can employ full-device encryption or container-based encryption to protect the confidentiality of CUI on mobile devices and computing platforms. Container-based encryption provides a more fine-grained approach to the encryption of data and information including encrypting selected data structures such as files, records, or fields. See [NIST CRYPTO].
Assessment GuidanceExamine 0/8
How an assessor determines this requirement is met. Source: CMMC Assessment Guide – Level 2, Version 2.13 (NIST SP 800-171 Rev. 2).
Discussion
Ensure CUI is encrypted on all mobile devices and mobile computing platforms that process, store, or transmit CUI including smartphones, tablets, and e-readers.
Because the use of cryptography in this requirement is to protect the confidentiality of CUI, the cryptography used must meet the criteria specified in requirement SC.L2-3.13.11.
This requirement, AC.L2-3.1.19, specifies that CUI be encrypted on mobile devices and extends three other CUI protection requirements (MP.L2-3.8.1, MP.L2-3.8.2, and SC.L23.13.16):
MP.L2-3.8.1 requires that media containing CUI be protected. MP.L2-3.8.2 limits access to CUI to authorized users.
Finally, SC.L2-3.13.16 requires confidentiality of CUI at rest.
This requirement, AC.L2-3.1.19, also leverages SC.L2-3.13.11, which specifies that the algorithms used must be FIPS-validated cryptography, and SC.L2-3.13.10, which specifies that any cryptographic keys in use must be protected.
Examples
- Example 1
You are in charge of mobile device security for a company that processes CUI. You configure all laptops to use the full-disk encryption technology built into the operating system. This approach is FIPS-validated and encrypts all files, folders, and volumes.
- Example 2
Phones and tablets pose a greater technical challenge with their wide range of manufacturers and operating systems. You select a proprietary mobile device management (MDM) solution to enforce FIPS-validated encryption on those devices [a, b].
Assessment Methods
Not all of the evidence listed is required to meet this requirement — check the items your organization has collected.
- Personnel with access control responsibilities for mobile devices
- System or network administrators
- Personnel with information security responsibilities
- Encryption mechanisms protecting confidentiality of information on mobile devices