No remote activation of webcams or mics, and users should know when they're on.
What it actually means
Collaborative computing devices — webcams, microphones, conferencing devices — shouldn't be remotely activatable without the user's knowledge, and there must be a clear indication when they're in use. In practice the built-in on-air light and OS privacy controls usually satisfy this; document that remote activation is prohibited.
Pass or fail — an assessor needs a "yes" to each
- Is remote activation of cameras / mics prohibited by policy and configuration?
- Is there a visible or audible indication when these devices are active?
What to have ready
- Policy prohibiting remote activation
- Device / OS settings and the in-use indicator (camera light)
Where teams trip up
- Conferencing apps configured to auto-join with camera / mic on
- No policy addressing it at all
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in System & Communications Protection (3.13)
3.13.1 — Protect your boundaries3.13.2 — Build security in by design3.13.3 — Separate user and admin functions3.13.4 — Stop data leaking through shared resources3.13.5 — Wall off your public-facing systems3.13.6 — Deny all, permit by exception3.13.7 — Block split tunneling on VPNs3.13.8 — Encrypt CUI in transit3.13.9 — Drop idle network sessions3.13.10 — Manage your encryption keys3.13.11 — FIPS-validated cryptography3.13.13 — Control mobile code3.13.14 — Control and monitor VoIP3.13.15 — Protect session authenticity3.13.16 — Encrypt CUI at rest