1Overview
SC.L2-3.13.12 addresses cameras and microphones that could be activated without the user knowing. It requires that remote activation of collaborative computing devices be prohibited and that an indication of devices in use be provided to users present at the device, so that a webcam or microphone cannot be turned on remotely, unseen. It is a one-point requirement and may be deferred on a plan of action.
Collaborative computing devices, cameras, microphones, and similar, can capture the physical environment around a system. If they can be activated remotely without any indication, they become a surveillance risk: someone could turn on a camera or microphone without the people nearby knowing. This control requires two protections: remote activation of these devices is prohibited, and when they are in use, an indication is provided to users present at the device. The three assessment objectives are identifying the collaborative computing devices, prohibiting remote activation, and providing the in-use indication.
Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.
The requirement has two parts, and the assessment objectives add identification as the foundation. The collaborative computing devices are identified; remote activation of them is prohibited; and an indication of use is provided to users present at the device. The prohibition prevents unseen remote activation, and the indication ensures that when a device is active, the people nearby can tell. Together they keep these devices from becoming covert surveillance.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.13.12 into three objectives: identify the devices, provide the in-use indication, and prohibit remote activation.
Collaborative computing devices are identified. The cameras, microphones, and similar devices are known.
Collaborative computing devices provide indication to users of devices in use. People present at the device can tell when it is active, such as a camera or microphone in use.
Remote activation of collaborative computing devices is prohibited. The devices cannot be turned on remotely.
The three objectives are identify, prohibit remote activation, and provide the in-use indication. The common gaps are at [b] and [c], where remote activation is not actually prohibited or no clear in-use indication exists. The assessor looks for all three across the collaborative computing devices.
3Failure Patterns
The failures are about devices that can be activated or run unseen.
Remote activation possible
Where a camera or microphone can be turned on remotely, it becomes a covert surveillance risk. Prohibiting remote activation removes that path.
No in-use indication
A device that can be active without any indication to those present leaves people unaware they are being captured. An in-use indication makes activity visible.
Devices not identified
Without identifying the collaborative computing devices, the protections cannot be applied to them. Identification comes first.
4Ownership
This is an IT and system administration-owned control.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Identifies devices, prohibits remote activation, and ensures in-use indication. Owns the configuration evidence. |
| Security or compliance lead | Confirms remote activation is prohibited and indication is provided. |
| Program lead | Documents the collaborative computing device controls. |
5Tooling
The control is delivered by device configuration and hardware indicators.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Device inventory | Identified collaborative computing devices. |
| [b] | Hardware indicator lights, in-use signals | Indication of use to those present. |
| [c] | Configuration prohibiting remote activation | Devices cannot be turned on remotely. |
The caveat is that both the prohibition and the indication have to actually function. A policy against remote activation that is not enforced, or a device with no working in-use indicator, leaves objectives unmet. The assessor examines all three, so identification, prohibition, and indication have to hold.
6Evidence
The satisfied version of 3.13.12 shows devices that cannot be remotely activated and signal use.
| Evidence | What it demonstrates |
|---|---|
| Device inventory | Objective [a]. Devices identified. |
| Configuration and indicators | Objectives [b], [c]. Use indicated and remote activation prohibited. |
The evidence should show collaborative computing devices identified, remote activation prohibited, and an in-use indication provided to those present. The device inventory together with the configuration and indicators is the clearest demonstration of the control.
A camera should not turn on unseen
Collaborative devices can become covert surveillance if activated remotely without indication, so this control asks that remote activation be prohibited and use be signaled to those present. Configuring those protections is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.12. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.12[a] through 3.13.12[c]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov