1Overview
AC.L2-3.1.21 narrows the external-systems concern of the previous control to a specific and common vector: the portable storage device that a person carries from the organization's environment to an external system. It requires that the use of such devices on external systems be limited, closing a path by which CUI, or malware, moves between the controlled environment and systems the organization does not manage.
The concern runs in both directions. A thumb drive that leaves the environment holding CUI and is plugged into a home computer carries controlled data onto an unverified system; the same drive plugged back in can carry malware from that outside system into the environment. Because portable storage is small, personal, and easy to move without thought, it is a quiet channel across the boundary that formal network controls do not see. The control asks the organization to limit the use of portable storage on external systems, whether by restricting which devices may be used, prohibiting the practice, or controlling it under defined conditions, so that this easy path across the boundary is deliberately governed rather than left open.
Limit use of portable storage devices on external systems.
The requirement addresses portable storage devices, thumb drives, external drives, memory cards, used on external systems, meaning systems outside the organization's authorization boundary. "Limit use" ranges from restricting the practice to specific organization-controlled devices, to prohibiting the use of organizational portable storage on external systems entirely, to controlling it under conditions the organization sets. The organization decides the degree of limitation appropriate to its environment, and the control is satisfied when that limit is defined and enforced rather than left to individual habit.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.1.21 into three objectives: identify and document the use of portable storage on external systems, define the limits on that use, and enforce those limits.
The use of portable storage devices containing CUI on external systems is identified and documented. The organization has defined how, and whether, its portable storage may be used on external systems.
Limits on the use of portable storage devices containing CUI on external systems are defined. The specific restrictions are written down: which devices, under what conditions, or an outright prohibition, so there is a defined limit to enforce.
The use of portable storage devices containing CUI on external systems is limited as defined. The defined limit is enforced, so the practice is actually constrained rather than only discouraged on paper.
The three objectives move from documenting the practice to defining its limits to enforcing them, the pattern seen throughout this family. The common gap is at objective [c], where a policy discourages using organizational drives on outside systems while no technical control makes the limit real, so the practice continues out of habit. The assessor looks for enforcement that constrains the use, not merely a statement against it.
3Failure Patterns
The failures are about portable storage moving across the boundary without limit, and about a policy that exists without any enforcement behind it.
The drive that goes everywhere
A personal thumb drive used to move files between the shop, home, and a customer site travels across the boundary repeatedly, carrying CUI out and potentially carrying malware back. Without a defined and enforced limit, this everyday convenience is an unmonitored channel between the environment and every external system the drive touches.
Policy without enforcement
A policy may state that organizational portable storage is not to be used on external systems while nothing technically restricts it, so objective [c] fails even though [a] and [b] are documented. Removable-media controls or device restrictions have to make the limit real, since a rule against a convenient practice that nothing enforces will not hold.
No distinction between organizational and personal drives
Where the organization has not defined which portable storage is permitted, personal drives of unknown provenance are used freely in the environment and organizational drives leave it without control. Defining and controlling the permitted devices, and prohibiting the rest, is what gives this control something to enforce.
Unencrypted drives crossing the boundary
Even where some use is permitted, portable storage that carries CUI onto external systems without encryption exposes the data if the drive is lost or the external system is compromised. This ties to the media protection family, and an encrypted, controlled device is the minimum where portable storage is allowed to cross the boundary at all.
4Ownership
This is an IT-owned control with a policy decision behind it about whether portable storage may cross the boundary at all, and its enforcement overlaps with the broader removable-media controls of the media protection family.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Enforces the defined limit through removable-media controls, device restrictions, and encryption of permitted devices. Owns the technical evidence. |
| Security or compliance lead | Defines the limit on portable storage use on external systems, whether prohibition or controlled use, and confirms enforcement makes it real. |
| Department supervisors | Reinforce the practice on the floor, since portable storage habits are workflow habits, and a limit that ignores how files actually move will be worked around. |
| Program lead | Includes portable storage in periodic review and retains the policy and enforcement records. |
5Tooling
The control is enforced with removable-media controls and device policy, the same tooling that governs portable storage generally, applied to the crossing of the boundary.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Portable storage policy in the access and media policy | The defined limit on using portable storage on external systems, whether prohibition or controlled conditions. |
| [c] enforcement | Group Policy or Intune removable-storage controls, device control policies | Restricting or blocking portable storage use, and permitting only approved, controlled devices where use is allowed. |
| [c] protection | BitLocker To Go or equivalent encryption on permitted devices | Encrypting the permitted portable storage so that CUI crossing the boundary is protected if the device is lost. |
| Verification | Device control logs and policy reports | Evidence that the limit is enforced across the environment, showing which devices are permitted and that others are blocked. |
The caveat is that a workable limit accounts for how files actually move. A blanket prohibition that ignores a legitimate need for portable media will be circumvented, so the durable approach is often a small set of controlled, encrypted devices for the genuine cases and enforcement against the rest. The assessor tests objective [c] by checking whether portable storage use is actually constrained, so the enforcement has to be present rather than only the policy.
6Evidence
The satisfied version of 3.1.21 shows the defined limit and its enforcement across the environment.
| Evidence | What it demonstrates |
|---|---|
| Portable storage policy | Objective [a]. The defined limit on using portable storage on external systems. |
| Removable-media control configuration | Objective [c]. The enforcement restricting or blocking portable storage use. |
| Approved device list | Objectives [a], [b]. Where use is permitted, the controlled, encrypted devices allowed and the exclusion of others. |
| Device control logs | Objective [c]. Records showing the limit in operation across the environment. |
The evidence should show that the limit is enforced rather than merely stated, through the removable-media controls that constrain the practice, and where use is permitted, that the allowed devices are controlled and encrypted. Configuration and logs demonstrating that portable storage use is actually limited, paired with the defined policy, are the clearest demonstration of the control.
The thumb drive is the boundary nobody watches
Portable storage crosses the boundary in a pocket, and a policy alone will not stop it. Defining a workable limit that accounts for how files really move, providing controlled encrypted devices for the legitimate cases, and enforcing against the rest is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.21. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.21[a] through 3.1.21[c]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov