NIST 800-171 Controls · Access Control
AC.2.021 — Limit Use of Portable Storage on External Systems
Limit use of portable storage devices on external systems.
What AC.2.021 means in plain English
Your employees shouldn't be plugging company USB drives (containing CUI or work data) into computers you don't control — like a customer's computer, a public library PC, or a personal home computer. And external USB drives from unknown sources shouldn't be plugged into your company machines. This prevents malware from jumping in on a USB stick and prevents data from walking out the door on a thumb drive.
The assessment question
“Do you have policies and/or technical controls that prevent employees from using company USB storage devices on external/unmanaged computers, and that prevent unknown or unauthorized USB devices from being inserted into company computers that store or process CUI?”
How to implement AC.2.021
- Write a clear policy: "Company USB drives may only be used on company-owned and managed computers. Do not insert company USB drives into personal computers, customer computers, or any unmanaged device. Do not insert personal or unknown USB drives into company computers."
- Use Microsoft Defender for Business (included in M365 Business Premium) Device Control to restrict USB storage device usage: go to Microsoft Intune > Endpoint Security > Attack surface reduction > Device control. Create a policy that blocks unknown/unmanaged USB storage devices.
- For computers where USB blocking is not feasible, use Windows Group Policy to disable AutoPlay and AutoRun for USB drives: Computer Configuration > Administrative Templates > Windows Components > AutoPlay Policies > Turn off AutoPlay — set to All Drives.
- If you need to exchange files with external parties, use an approved method (secure email via M365, SharePoint sharing links with expiration) rather than USB drives.
- Conduct periodic checks: ask employees how they transfer files to and from work computers. If USB drives are common, accelerate the technical controls above.
Evidence your assessor will ask for
- Written Portable Storage Policy or Removable Media Policy
- Defender for Business or Intune Device Control policy screenshot showing USB restrictions
- Group Policy AutoRun disable configuration screenshot
- Employee training acknowledgment of the portable storage policy
Does AI prompt monitoring help with this control? Honestly, no.
AC.2.021 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Access Control controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.