STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

SC-42

System and Communications ProtectionRev 5system

Sensor Capability and Data

Control Statement

a. Prohibit [Selection: organization-defined value] ; and b. Provide an explicit indication of sensor use to [Assignment: group of users].

Supplemental Guidance

Sensor capability and data applies to types of systems or system components characterized as mobile devices, such as cellular telephones, smart phones, and tablets. Mobile devices often include sensors that can collect and record data regarding the environment where the system is in use. Sensors that are embedded within mobile devices include microphones, cameras, Global Positioning System (GPS) mechanisms, and accelerometers. While the sensors on mobiles devices provide an important function, if activated covertly, such devices can potentially provide a means for adversaries to learn valuable information about individuals and organizations. For example, remotely activating the GPS function on a mobile device could provide an adversary with the ability to track the movements of an individual. Organizations may prohibit individuals from bringing cellular telephones or digital cameras into certain designated facilities or controlled areas within facilities where classified information is stored or sensitive conversations are taking place.

Related Controls (1)

SC-15

CCI Identifiers (6)

CCI-002547Defines the exceptions where remote activation of sensors is allowed.CCI-002556Defines the environmental sensing capabilities prohibited on devices used in organization-defined facilities, areas, or systems.CCI-002557Defines the facilities, areas, or systems where devices processing organization-defined environmental sensing capabilities are prohibited.CCI-002548Prohibit the use of devices possessing organization-defined environmental sensing capabilities in organization-defined facilities, areas, or systems; and/or the remote activation of environmental sensing capabilities on organizational systems or system components except for the organization-defined exceptions where remote activation of sensors is allowed.CCI-002549Defines the class of users to receive explicit indication of sensor use.CCI-002550Provide an explicit indication of sensor use to the organization-defined class of users.

Linked STIG Checks (0)

No STIG checks reference this control.