Phones, tablets, and laptops carrying CUI must be encrypted.
What it actually means
Encrypt CUI on mobile devices and mobile computing platforms — laptops, phones, tablets. Full-disk encryption on laptops and device encryption or MDM policy on phones and tablets satisfies this. Pair it with FIPS-validated cryptography (3.13.11).
Pass or fail — an assessor needs a "yes" to each
- Is encryption enforced on all mobile devices that store CUI (laptops, phones, tablets)?
- Is it enforced by policy / MDM rather than left to the user?
What to have ready
- MDM / encryption policy and compliance report
- Device encryption status
Where teams trip up
- BYOD phones with CUI and no enforced encryption
- Laptops encrypted but tablets and phones ignored
A 3-point control. Overlaps with 3.13.16 (CUI at rest) — handle device encryption once, centrally, and it covers both.
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
3.13.16 — Encrypting CUI at rest3.1.18 — Controlling mobile devices3.13.11 — FIPS-validated cryptography
More in Access Control (3.1)
3.1.1 — Limit who (and what) can get in3.1.2 — Limit what users can do3.1.3 — Control the flow of CUI3.1.4 — Separate duties3.1.5 — Least privilege (especially for admins)3.1.6 — Use non-privileged accounts for routine work3.1.7 — Restrict and log privileged functions3.1.8 — Limit failed logons3.1.9 — Show privacy and security notices3.1.10 — Lock idle screens3.1.11 — End sessions automatically3.1.12 — Monitor and control remote access3.1.13 — Encrypt remote access sessions3.1.14 — Funnel remote access through managed points3.1.15 — Authorize privileged remote actions3.1.16 — Authorize wireless access first3.1.17 — Protect wireless with authentication + encryption3.1.18 — Control mobile device connections3.1.20 — Control connections to external systems3.1.21 — Limit portable storage on external systems3.1.22 — Control what goes on public systems