NIST 800-171 R-3.1.21
Limit Portable Storage on External Systems
Official citation: 3.1.21
Class: core · Severity: medium
Statement of the obligation — verify against source
3.1.21
What it means
Limit the use of organization-controlled portable storage devices (such as USB drives) on external systems — either prohibiting them outright or restricting how and under what conditions they may be used. As with 3.1.20, 'external' can include your own systems that don't process CUI, viewed from the perspective of a CUI system.
Educational reference only — not legal advice. Consult a qualified assessor or attorney for binding compliance determinations.