Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family AC

AC-19Access Control for Mobile Devices

Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and Authorize the connection of mobile devices to organizational systems.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (27)

Weaknesses this control addresses (5)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization8,680The control requires authorization before allowing mobile device connections, directly mitigating missing authorization for system access.
CWE-284Improper Access Control4,832Requiring authorization and configuration controls for mobile device connections directly enforces access control and prevents unauthorized devices from reaching organizational systems.
CWE-863Incorrect Authorization3,234Establishing connection authorization processes for mobile devices helps ensure authorization decisions are correctly implemented rather than incorrect.
CWE-306Missing Authentication for Critical Function2,567Authorizing mobile device connections to organizational systems ensures authentication is performed for this critical access function.
CWE-285Improper Authorization1,230Mandating explicit authorization of mobile device connections reduces the risk of improper authorization decisions for system access.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-05901.57.50.0014good
CVE-2025-12982.09.80.0018partial
CVE-2024-116241.67.80.0001good
CVE-2025-24200 KEV6.16.10.4816good
CVE-2025-431922.09.80.0011partial
CVE-2024-539311.89.10.0014partial
CVE-2025-257581.57.50.0013good
CVE-2025-200601.57.50.0017good
CVE-2025-211941.47.10.0019partial
CVE-2025-01501.47.10.0015partial
CVE-2024-441360.94.60.0030partial

Other controls in family AC

AC-1 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-17 AC-18 AC-2 AC-20 AC-21 AC-22 AC-23 AC-24 AC-25 AC-3 AC-4 AC-5 AC-6 AC-7 AC-8 AC-9