← Controls / SC

SC-42 Sensor Capability and Data

System and Communications Protection

Description

a. Prohibit [Selection (one or more): the use of devices possessing [Assignment: organization-defined environmental sensing capabilities] in [Assignment: organization-defined facilities, areas, or systems]; the remote activation of environmental sensing capabilities on organizational systems or system components with the following exceptions: [Assignment: organization-defined exceptions where remote activation of sensors is allowed]]; and b. Provide an explicit indication of sensor use to [Assignment: organization-defined group of users].

Supplemental Guidance

Sensor capability and data applies to types of systems or system components characterized as mobile devices, such as cellular telephones, smart phones, and tablets. Mobile devices often include sensors that can collect and record data regarding the environment where the system is in use. Sensors that are embedded within mobile devices include microphones, cameras, Global Positioning System (GPS) mechanisms, and accelerometers. While the sensors on mobiles devices provide an important function, if activated covertly, such devices can potentially provide a means for adversaries to learn valuable information about individuals and organizations. For example, remotely activating the GPS function on a mobile device could provide an adversary with the ability to track the movements of an individual. Organizations may prohibit individuals from bringing cellular telephones or digital cameras into certain designated facilities or controlled areas within facilities where classified information is stored or sensitive conversations are taking place.

Changes from Rev 4

No significant title changes from Rev 4.

Enhancements (4)

What NIST adds to this control. Select one to read its statement.

SC-42(01) Reporting to Authorized Individuals or Roles

Verify that the system is configured so that data or information collected by the [Assignment: organization-defined sensors] is only reported to authorized individuals or roles.

SC-42(02) Authorized Use

Employ the following measures so that data or information collected by [Assignment: organization-defined sensors] is only used for authorized purposes: [Assignment: organization-defined measures].

SC-42(04) Notice of Collection

Employ the following measures to facilitate an individual’s awareness that personally identifiable information is being collected by [Assignment: organization-defined sensors]: [Assignment: organization-defined measures].

SC-42(05) Collection Minimization

Employ [Assignment: organization-defined sensors] that are configured to minimize the collection of information about individuals that is not needed.

Withdrawn by NIST:

  • SC-42(03) Prohibit Use of Devices, now in SC-42

Compliance Mappings

SOC 2 TSC

P1.0P1.3

CSA CCM v4

UEM-01

CSA AICM v1

UEM-01

BSI IT-Grundschutz

CON.7OPS.1.2.4SYS.2.1

FINMA Circular 2023/1

IV.D(78)

OSFI B-13

B-13.3.3

RBI CSF

Annex1.15

DNB Good Practice

DNB.20.1

BoM CTRM

3.12

BOT Cyber Resilience

Ch2.6