Only managed, compliant phones and tablets can connect to CUI.
What it actually means
Phones and tablets that touch CUI must be brought under management (MDM, e.g., Intune) with conditional access — only enrolled, compliant devices connect. Unmanaged personal phones reaching CUI is exactly what this control stops.
Pass or fail — an assessor needs a "yes" to each
- Mobile devices that access CUI are enrolled in MDM.
- Conditional access blocks non-compliant devices.
- A policy governs what mobile devices may connect and how.
What to have ready
- MDM (Intune) enrollment + compliance policies
- Conditional-access policy
- Mobile device policy
Where teams trip up
- Personal phones syncing CUI email with no management
- No conditional access — any device can connect once logged in
- BYOD with no enrollment requirement
Not Applicable only if no mobile devices connect to CUI (document it).
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Access Control (3.1)
3.1.1 — Limit who (and what) can get in3.1.2 — Limit what users can do3.1.3 — Control the flow of CUI3.1.4 — Separate duties3.1.5 — Least privilege (especially for admins)3.1.6 — Use non-privileged accounts for routine work3.1.7 — Restrict and log privileged functions3.1.8 — Limit failed logons3.1.9 — Show privacy and security notices3.1.10 — Lock idle screens3.1.11 — End sessions automatically3.1.12 — Monitor and control remote access3.1.13 — Encrypt remote access sessions3.1.14 — Funnel remote access through managed points3.1.15 — Authorize privileged remote actions3.1.16 — Authorize wireless access first3.1.17 — Protect wireless with authentication + encryption3.1.19 — Encrypt CUI on mobile devices3.1.20 — Control connections to external systems3.1.21 — Limit portable storage on external systems3.1.22 — Control what goes on public systems