DKDavid Koran& Associates
Home The CMMC Guide Part III · Media Protection MP.L2-3.8.8
The CMMC Guide · Media Protection Family

MP.L2-3.8.8  Prohibit Unowned Portable Storage

Prohibit the use of portable storage devices when such devices have no identifiable owner.

Family
Media ProtectionMP, 9 requirements
Point Value
3Weighted above baseline
POA&M Eligible
NoAbove one point, cannot be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

MP.L2-3.8.8 bans anonymous storage devices. It requires that the organization prohibit the use of portable storage devices when such devices have no identifiable owner, so that unknown devices, the classic found USB drive, cannot be introduced into the environment. It is a three-point requirement with a single assessment objective, and it cannot be deferred on a plan of action.

A portable storage device with no identifiable owner is a device no one is accountable for and no one can vouch for. The found USB drive is a well-known attack vector: an attacker leaves a device to be picked up and plugged in, and it carries malware into the environment. This control prohibits using such ownerless devices, so that any portable storage device connected to systems is one with a known, accountable owner. It removes the anonymous device as an entry path.

The requirement · NIST SP 800-171 Rev 2, 3.8.8

Prohibit the use of portable storage devices when such devices have no identifiable owner.

The requirement is a specific prohibition: portable storage devices without an identifiable owner may not be used. An identifiable owner means the device is accountable to a known person or the organization, rather than being of unknown origin. The single assessment objective is that the use of such ownerless devices is prohibited, whether enforced through technical device control, policy, or both.

2The Assessment Objective

NIST SP 800-171A frames 3.8.8 as a single objective: prohibit portable storage devices with no identifiable owner.

The use of portable storage devices is prohibited when such devices have no identifiable owner. Ownerless devices cannot be used.

MeetsPortable storage devices without an identifiable owner are prohibited from use.
FailsDevices of unknown origin can be plugged in and used.

The single objective is the prohibition on ownerless devices. The common failure is a found or unknown device being used because nothing stops it. The assessor looks for a prohibition, enforced technically or by policy, on portable storage with no identifiable owner.

3Failure Patterns

The failures are about anonymous devices being used.

The found USB drive

A device of unknown origin picked up and plugged in can carry malware straight into the environment. Prohibiting ownerless devices removes this classic entry path.

No ownership requirement

Where there is no requirement that devices have an identifiable owner, anonymous devices are used by default. Requiring identifiable ownership is the basis of the prohibition.

Prohibition not enforced

A stated ban on unknown devices that is not enforced leaves the actual use unrestricted. The prohibition has to be real, through device control or enforced policy.

The common root
This control fails when an unknown device is treated as usable. A device with no identifiable owner is one no one is accountable for, and plugging it in trusts something of unknown origin, which is exactly what the found-drive attack relies on. Prohibiting ownerless devices removes that trust.

4Ownership

This is an IT-owned control with a policy dimension.

RoleResponsibility for this control
IT and system administratorEnforces the prohibition on ownerless portable storage, through device control where possible. Owns the technical evidence.
Security or compliance leadDefines the identifiable-owner requirement and confirms the prohibition is enforced.
Program leadIncludes the prohibition in policy and retains the evidence.
See also: This control works with the removable media control of MP.L2-3.8.7, narrowing it to the specific case of ownerless devices.

5Tooling

The control is delivered by device control and enforced policy prohibiting ownerless devices.

ObjectiveToolingWhat it provides
technicalDevice control, allowed-device listsTechnical enforcement that only known devices are used.
policyProhibition on ownerless devicesGovernance banning devices of unknown origin.

The caveat is that the prohibition has to be enforced, not just stated. Device control that permits only known devices provides the strongest enforcement, while policy alone depends on being genuinely followed. The assessor examines whether ownerless devices are actually prohibited, so the enforcement has to be real.

6Evidence

The satisfied version of 3.8.8 shows ownerless devices prohibited.

EvidenceWhat it demonstrates
Device control configurationThe objective. Only known devices permitted.
Portable storage policyThe objective. Ownerless devices prohibited.

The evidence should show the use of portable storage devices with no identifiable owner prohibited and enforced. The device control configuration and the policy are the clearest demonstration, and because this control cannot sit on a plan of action, the prohibition has to be real at the time of assessment.

An unknown device is an untrusted one

A portable storage device with no identifiable owner is something no one is accountable for, and plugging it in is exactly the found-drive attack, so this three-point control prohibits it. Enforcing an identifiable-owner requirement on portable storage is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.8. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.8.8. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing MP.L2-3.8.8 among the three-point derived security requirements. ecfr.gov
← Previous in Media Protection
MP.L2-3.8.7 · Control Removable Media
Next in Media Protection →
MP.L2-3.8.9 · Protect Backup CUI
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MP.L2-3.8.8 · Edition 2026.1 · Last reviewed July 12, 2026