Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family AC

AC-19Access Control for Mobile Devices

Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and Authorize the connection of mobile devices to organizational systems.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (27)

Weaknesses this control addresses (5)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization10,200+The control requires authorization before allowing mobile device connections, directly mitigating missing authorization for system access.
CWE-284Improper Access Control6,900+Requiring authorization and configuration controls for mobile device connections directly enforces access control and prevents unauthorized devices from reaching organizational systems.
CWE-863Incorrect Authorization3,900+Establishing connection authorization processes for mobile devices helps ensure authorization decisions are correctly implemented rather than incorrect.
CWE-306Missing Authentication for Critical Function3,300+Authorizing mobile device connections to organizational systems ensures authentication is performed for this critical access function.
CWE-285Improper Authorization1,500+Mandating explicit authorization of mobile device connections reduces the risk of improper authorization decisions for system access.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family AC

AC-1 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-17 AC-18 AC-2 AC-20 AC-21 AC-22 AC-23 AC-24 AC-25 AC-3 AC-4 AC-5 AC-6 AC-7 AC-8 AC-9