DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.12
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.12  Control Collaborative Computing Devices

Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

SC.L2-3.13.12 addresses cameras and microphones that could be activated without the user knowing. It requires that remote activation of collaborative computing devices be prohibited and that an indication of devices in use be provided to users present at the device, so that a webcam or microphone cannot be turned on remotely, unseen. It is a one-point requirement and may be deferred on a plan of action.

Collaborative computing devices, cameras, microphones, and similar, can capture the physical environment around a system. If they can be activated remotely without any indication, they become a surveillance risk: someone could turn on a camera or microphone without the people nearby knowing. This control requires two protections: remote activation of these devices is prohibited, and when they are in use, an indication is provided to users present at the device. The three assessment objectives are identifying the collaborative computing devices, prohibiting remote activation, and providing the in-use indication.

The requirement · NIST SP 800-171 Rev 2, 3.13.12

Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.

The requirement has two parts, and the assessment objectives add identification as the foundation. The collaborative computing devices are identified; remote activation of them is prohibited; and an indication of use is provided to users present at the device. The prohibition prevents unseen remote activation, and the indication ensures that when a device is active, the people nearby can tell. Together they keep these devices from becoming covert surveillance.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.13.12 into three objectives: identify the devices, provide the in-use indication, and prohibit remote activation.

[a]

Collaborative computing devices are identified. The cameras, microphones, and similar devices are known.

MeetsCollaborative computing devices are identified.
FailsThe devices are not identified.
[b]

Collaborative computing devices provide indication to users of devices in use. People present at the device can tell when it is active, such as a camera or microphone in use.

MeetsAn indication of use is provided to users present at the device.
FailsDevices can be in use without indication to those present.
[c]

Remote activation of collaborative computing devices is prohibited. The devices cannot be turned on remotely.

MeetsRemote activation of the devices is prohibited.
FailsDevices can be activated remotely.

The three objectives are identify, prohibit remote activation, and provide the in-use indication. The common gaps are at [b] and [c], where remote activation is not actually prohibited or no clear in-use indication exists. The assessor looks for all three across the collaborative computing devices.

3Failure Patterns

The failures are about devices that can be activated or run unseen.

Remote activation possible

Where a camera or microphone can be turned on remotely, it becomes a covert surveillance risk. Prohibiting remote activation removes that path.

No in-use indication

A device that can be active without any indication to those present leaves people unaware they are being captured. An in-use indication makes activity visible.

Devices not identified

Without identifying the collaborative computing devices, the protections cannot be applied to them. Identification comes first.

The common root
This control fails when the surveillance potential of everyday devices is overlooked. A webcam or microphone is convenient for collaboration, but the same capability, activated remotely and without indication, is covert monitoring. Prohibiting remote activation and signaling use is what keeps these devices from watching unseen.

4Ownership

This is an IT and system administration-owned control.

RoleResponsibility for this control
IT and system administratorIdentifies devices, prohibits remote activation, and ensures in-use indication. Owns the configuration evidence.
Security or compliance leadConfirms remote activation is prohibited and indication is provided.
Program leadDocuments the collaborative computing device controls.
See also: This control complements the physical protection family and the mobile-code and VoIP controls of SC.L2-3.13.13 and SC.L2-3.13.14.

5Tooling

The control is delivered by device configuration and hardware indicators.

ObjectivesToolingWhat it provides
[a]Device inventoryIdentified collaborative computing devices.
[b]Hardware indicator lights, in-use signalsIndication of use to those present.
[c]Configuration prohibiting remote activationDevices cannot be turned on remotely.

The caveat is that both the prohibition and the indication have to actually function. A policy against remote activation that is not enforced, or a device with no working in-use indicator, leaves objectives unmet. The assessor examines all three, so identification, prohibition, and indication have to hold.

6Evidence

The satisfied version of 3.13.12 shows devices that cannot be remotely activated and signal use.

EvidenceWhat it demonstrates
Device inventoryObjective [a]. Devices identified.
Configuration and indicatorsObjectives [b], [c]. Use indicated and remote activation prohibited.

The evidence should show collaborative computing devices identified, remote activation prohibited, and an in-use indication provided to those present. The device inventory together with the configuration and indicators is the clearest demonstration of the control.

A camera should not turn on unseen

Collaborative devices can become covert surveillance if activated remotely without indication, so this control asks that remote activation be prohibited and use be signaled to those present. Configuring those protections is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.12. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.12[a] through 3.13.12[c]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.11 · FIPS-Validated Cryptography
Next in System and Communications Protection →
SC.L2-3.13.13 · Control and Monitor Mobile Code
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.12 · Edition 2026.1 · Last reviewed July 12, 2026