STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

SC-41

System and Communications ProtectionRev 5organization

Port and I/O Device Access

Control Statement

[Selection: organization-defined value] disable or remove [Assignment: connection ports or input/output devices] on the following systems or system components: [Assignment: systems or system components].

Supplemental Guidance

Connection ports include Universal Serial Bus (USB), Thunderbolt, and Firewire (IEEE 1394). Input/output (I/O) devices include compact disc and digital versatile disc drives. Disabling or removing such connection ports and I/O devices helps prevent the exfiltration of information from systems and the introduction of malicious code from those ports or devices. Physically disabling or removing ports and/or devices is the stronger action.

Related Controls (2)

AC-20MP-7

CCI Identifiers (3)

CCI-002544Defines the systems or system components on which organization-defined connection ports or input/output devices are to be physically or logically disabled or removed.CCI-002545Defines the connection ports or input/output devices that are to be physically or logically disabled or removed from organization-defined systems or system components.CCI-002546Physically or logically disable or remove organization-defined connection ports or input/output devices on organization-defined systems or system components.

Linked STIG Checks (22)

Across 22 STIGs. Click to expand.