{"data":{"id":"SC-41","name":"Port and I/O Device Access","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"[Selection (one): Physically; Logically] disable or remove [Assignment: organization-defined connection ports or input/output devices] on the following systems or system components: [Assignment: organization-defined systems or system components].","supplemental_guidance":"Connection ports include Universal Serial Bus (USB), Thunderbolt, and Firewire (IEEE 1394). Input/output (I/O) devices include compact disc and digital versatile disc drives. Disabling or removing such connection ports and I/O devices helps prevent the exfiltration of information from systems and the introduction of malicious code from those ports or devices. Physically disabling or removing ports and/or devices is the stronger action.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-41","name":"Port and I/O Device Access","description":"[Selection (one): Physically; Logically] disable or remove [Assignment: organization-defined connection ports or input/output devices] on the following systems or system components: [Assignment: organization-defined systems or system components].","discussion":"Connection ports include Universal Serial Bus (USB), Thunderbolt, and Firewire (IEEE 1394). Input/output (I/O) devices include compact disc and digital versatile disc drives. Disabling or removing such connection ports and I/O devices helps prevent the exfiltration of information from systems and the introduction of malicious code from those ports or devices. Physically disabling or removing ports and/or devices is the stronger action.","related_controls":["AC-20","MP-07"],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":["8.1"],"cobit_2019":["DSS05"],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["11"],"pra_op_resilience":[],"bsi_grundschutz":["NET.3.1"],"anssi":[],"osfi_b13":["B-13.3.2"],"finma_circular":[],"gdpr":[],"dora":[],"bio2":["8.1"],"rbi_csf":["Annex1.4"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":["TME1.11.1","TME1.11.3"],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.I.2j"],"swift_cscf":[],"cbb_tm":["TM-8"],"cbuae":["CR-7"],"sama_csf":["3.3"],"bog_cisd":["CISD-VI"],"cbe_csf":["CTO-6","CTO-7"],"cbn_csf":["Part3.3"],"sa_js2":["JS2-7.2","JS2-8.4"],"bot_cyber":["Ch2.6"],"sebi_cscrf":["PR.ES"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1025","name":"Data from Removable Media","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Physically disabling or removing USB ports and removable media interfaces prevents adversaries from accessing and collecting data stored on removable media attached to protected systems."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Disabling or removing physical I/O ports, including USB and Thunderbolt, prevents adversaries from connecting removable storage devices for physical exfiltration of data from protected systems."},{"id":"T1091","name":"Replication Through Removable Media","tactics":["initial-access","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Physically disabling or removing USB and other removable media interfaces prevents malware from replicating through infected removable devices, blocking both initial access and lateral movement."},{"id":"T1200","name":"Hardware Additions","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Disabling or removing physical connection ports prevents adversaries from introducing unauthorized hardware additions such as rogue network adapters, keystroke loggers, or hardware implants."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Physically disabling USB ports prevents adversaries from connecting USB storage devices for data exfiltration, eliminating the physical channel required for USB-based data theft."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}