NIST 800-171 Controls · Access Control
AC.2.018 — Control Connection of Mobile Devices
Control connection of mobile devices.
What AC.2.018 means in plain English
If your employees use smartphones or tablets to access company email, files, or systems — or if they connect personal phones to company Wi-Fi — you need to have rules and controls around that. A personal phone that hasn't been updated in two years and has no PIN code shouldn't have access to your CUI. You should know which mobile devices connect to your systems and be able to wipe them remotely if they're lost or stolen.
The assessment question
“Do you have policies and technical controls governing which mobile devices (smartphones, tablets) can access company systems and data — for example, requiring devices to have a PIN/password, be enrolled in Mobile Device Management (MDM), or be company-owned — and can you remotely wipe a lost or stolen device that had access to CUI?”
How to implement AC.2.018
- Enroll all mobile devices that access company data into a Mobile Device Management (MDM) solution. Microsoft Intune (included with M365 Business Premium) is the most practical option — it lets you enforce PIN requirements, encryption, and remote wipe.
- Set a baseline mobile device policy in Intune or your MDM: require a 6-digit PIN or biometric unlock, require device encryption (enabled by default on modern iOS and Android), and configure automatic remote wipe after 10 failed unlock attempts.
- If you don't want to use MDM, at minimum implement a written policy requiring employees to: use a PIN, keep the OS updated, and never store CUI directly on personal devices (use SharePoint/OneDrive with the mobile app instead).
- Register and inventory every mobile device that accesses company resources. Include device type, owner, OS version, and enrollment date in your device inventory.
- Consider a "company-owned, personally-enabled" (COPE) approach for devices that regularly handle CUI: the company provides a dedicated work phone/tablet, maintaining full control.
Evidence your assessor will ask for
- MDM enrollment list showing all authorized mobile devices
- MDM policy configuration screenshot showing PIN, encryption, and remote wipe requirements
- Written Mobile Device Policy covering access rules, security requirements, and incident procedures
- Device inventory list with device type, owner, OS version, and access level
Does AI prompt monitoring help with this control? Honestly, no.
AC.2.018 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Access Control controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.