Requirements / System and Communications Protection (SC)
SC.L2-3.13.12
Collaborative Device Control
Official Source Material
Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.
Determine if:
- [a] collaborative computing devices are identified;
- [b] collaborative computing devices provide indication to users of devices in use; and
- [c] remote activation of collaborative computing devices is prohibited.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Laptop cameras and microphones are collaborative computing devices.
The requirement's discussion names networked whiteboards, cameras, and microphones, and excludes only dedicated video conferencing systems that activate when a participant connects the call. Inventory the built-in cameras and microphones across the fleet along with any room systems, and [a] is done. An organization with no conference room gear does not get to answer not applicable.
Indication of use is mostly built in. Write down what you rely on.
The hardware light beside the camera, the operating system's on-screen microphone indicator, and the meeting client's in-call display each signal a device in use, which answers [b]. A room device with no indicator gets a manual substitute: a posted notice or a locked door while in use.
Prohibit remote activation with configuration, and use camera covers where configuration cannot reach.
Disable auto-answer on room video units so nothing activates until someone accepts the call, and keep remote control of endpoint cameras away from standard users. Physical camera covers are a zero-cost supplement for [c].
Edge cases
- Remote support tools that can open a camera during a session are remote access, not collaborative computing devices. Configure them to require the user to accept the session, which keeps activation in the hands of the person at the device.
- A dedicated video conferencing system that activates only when a participant connects the call sits inside the requirement's own exclusion. Verify auto-answer is off, because that setting is the boundary of the exclusion.