1Overview
MP.L2-3.8.8 bans anonymous storage devices. It requires that the organization prohibit the use of portable storage devices when such devices have no identifiable owner, so that unknown devices, the classic found USB drive, cannot be introduced into the environment. It is a three-point requirement with a single assessment objective, and it cannot be deferred on a plan of action.
A portable storage device with no identifiable owner is a device no one is accountable for and no one can vouch for. The found USB drive is a well-known attack vector: an attacker leaves a device to be picked up and plugged in, and it carries malware into the environment. This control prohibits using such ownerless devices, so that any portable storage device connected to systems is one with a known, accountable owner. It removes the anonymous device as an entry path.
Prohibit the use of portable storage devices when such devices have no identifiable owner.
The requirement is a specific prohibition: portable storage devices without an identifiable owner may not be used. An identifiable owner means the device is accountable to a known person or the organization, rather than being of unknown origin. The single assessment objective is that the use of such ownerless devices is prohibited, whether enforced through technical device control, policy, or both.
2The Assessment Objective
NIST SP 800-171A frames 3.8.8 as a single objective: prohibit portable storage devices with no identifiable owner.
The use of portable storage devices is prohibited when such devices have no identifiable owner. Ownerless devices cannot be used.
The single objective is the prohibition on ownerless devices. The common failure is a found or unknown device being used because nothing stops it. The assessor looks for a prohibition, enforced technically or by policy, on portable storage with no identifiable owner.
3Failure Patterns
The failures are about anonymous devices being used.
The found USB drive
A device of unknown origin picked up and plugged in can carry malware straight into the environment. Prohibiting ownerless devices removes this classic entry path.
No ownership requirement
Where there is no requirement that devices have an identifiable owner, anonymous devices are used by default. Requiring identifiable ownership is the basis of the prohibition.
Prohibition not enforced
A stated ban on unknown devices that is not enforced leaves the actual use unrestricted. The prohibition has to be real, through device control or enforced policy.
4Ownership
This is an IT-owned control with a policy dimension.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Enforces the prohibition on ownerless portable storage, through device control where possible. Owns the technical evidence. |
| Security or compliance lead | Defines the identifiable-owner requirement and confirms the prohibition is enforced. |
| Program lead | Includes the prohibition in policy and retains the evidence. |
5Tooling
The control is delivered by device control and enforced policy prohibiting ownerless devices.
| Objective | Tooling | What it provides |
|---|---|---|
| technical | Device control, allowed-device lists | Technical enforcement that only known devices are used. |
| policy | Prohibition on ownerless devices | Governance banning devices of unknown origin. |
The caveat is that the prohibition has to be enforced, not just stated. Device control that permits only known devices provides the strongest enforcement, while policy alone depends on being genuinely followed. The assessor examines whether ownerless devices are actually prohibited, so the enforcement has to be real.
6Evidence
The satisfied version of 3.8.8 shows ownerless devices prohibited.
| Evidence | What it demonstrates |
|---|---|
| Device control configuration | The objective. Only known devices permitted. |
| Portable storage policy | The objective. Ownerless devices prohibited. |
The evidence should show the use of portable storage devices with no identifiable owner prohibited and enforced. The device control configuration and the policy are the clearest demonstration, and because this control cannot sit on a plan of action, the prohibition has to be real at the time of assessment.
An unknown device is an untrusted one
A portable storage device with no identifiable owner is something no one is accountable for, and plugging it in is exactly the found-drive attack, so this three-point control prohibits it. Enforcing an identifiable-owner requirement on portable storage is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.8. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.8.8. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing MP.L2-3.8.8 among the three-point derived security requirements. ecfr.gov