SC-42: Sensor Capability and Data

SC-42 requires organizations to restrict devices with environmental sensing capabilities in designated areas and disclose active sensor u...

Quick-reference card

FieldValue
Control IDSC-42
Control NameSensor Capability and Data
FrameworkNIST SP 800-53 Revision 5
Control FamilySystem and Communications Protection
Baselines
RelevanceSystem (First Party and Third Party)
Risk SeverityMedium

What this control requires

SC-42 requires organizations to restrict devices with environmental sensing capabilities in designated areas and disclose active sensor use to affected users. This control addresses a category of risk that most security programs overlook. Microphones, cameras, GPS receivers, and accelerometers embedded in everyday mobile devices collect data passively, often without any visibility from the security team.

In practice, organizations must define which facilities or areas prohibit sensor-equipped devices and establish enforceable policies around those restrictions. This means identifying where sensitive conversations, classified operations, or confidential data handling take place, then implementing controls that prevent unauthorized environmental data collection in those spaces.

The control also requires a notification mechanism. When sensors are active on organizational systems or components, designated users must receive an explicit indication of that activity. This dual requirement addresses both prevention and transparency, recognizing that some sensor use is legitimate while covert activation represents a direct threat to organizational security and individual privacy.

Why it matters

Unmanaged sensor capabilities on mobile devices create a surveillance channel that bypasses traditional network security controls entirely. A smartphone sitting on a conference table can capture audio, pinpoint location data, and even infer physical activity patterns through its accelerometer, all without generating the kind of network traffic that security teams typically monitor.

Failure to maintain this control introduces audit risk during federal assessments and compliance reviews. Auditors evaluating System and Communications Protection controls will look for documented policies governing sensor-equipped devices, evidence that those policies are enforced in practice, and proof that affected users receive notification when sensors are active.

The risk compounds in environments where sensitive discussions occur regularly. Government agencies, defense contractors, financial institutions, and organizations handling intellectual property all face scenarios where covert sensor activation could expose strategic plans, classified information, or privileged communications without triggering a single alert in their security operations center.

What attackers exploit

  • Remote sensor activation on mobile devices. Adversaries who compromise a device can silently enable microphones and cameras to capture conversations, meetings, and physical surroundings without the user’s knowledge.
  • GPS tracking through compromised applications. Malicious or compromised apps can activate location services to monitor an individual’s movements, revealing travel patterns, facility locations, and meeting schedules.
  • Accelerometer and gyroscope data exfiltration. Motion sensors can reveal behavioral patterns, movement habits, and physical activity data that support social engineering or physical surveillance of targeted individuals.
  • Covert camera access in sensitive facilities. Devices with camera capabilities in classified or restricted areas can be leveraged to photograph documents, whiteboard content, network diagrams, and physical security configurations.
  • Aggregated sensor data correlation. Combining GPS, audio, and motion data from multiple compromised devices produces a comprehensive intelligence picture that exceeds what any single sensor type could reveal alone.

How to implement

Most organizations fail at SC-42 not because they lack a sensor policy, but because their policy doesn’t translate into enforceable technical controls and verifiable user notification. The gap between “we prohibit phones in the SCIF” and “we can demonstrate that prohibition is enforced and monitored” is where audit findings live.

For your organization

Start by mapping every facility and area where environmental sensing capabilities pose a risk. This goes beyond obvious classified spaces to include executive conference rooms, legal offices, research labs, and any location where sensitive strategic or financial discussions take place. Document each designated area in your system and communications protection policy with specific justification for the restriction.

Define the scope of your prohibition clearly. Your policy should specify whether you prohibit all devices with sensing capabilities, only certain device types, or whether you allow exceptions with defined conditions. Exceptions need documented approval workflows and should identify which sensors may remain active, under what circumstances, and who authorized the exception.

Implement technical enforcement mechanisms where possible. Mobile device management (MDM) platforms can enforce sensor restrictions on enrolled organizational devices, disabling cameras or microphones in geofenced areas. For personally owned devices, you’ll need procedural controls like device collection points, storage lockers, or signal-blocking enclosures at facility entry points.

Build the notification component into your system architecture. When sensors are active on organizational systems or components, designated users need a visible and unambiguous indication. This could take the form of indicator lights, on-screen notifications, system tray icons, or audit log entries that users can review. The key requirement is that the indication is explicit, not buried in a settings menu.

Maintain audit evidence continuously. Collect system configuration records showing sensor restrictions, access control logs for designated areas, device management policy documentation, and periodic review records demonstrating that your controls remain effective. Common mistakes include treating this as a one-time policy exercise rather than an ongoing operational control, failing to update designated area lists when facilities change, and neglecting to test whether notification mechanisms function as documented.

For your vendors

When assessing vendor compliance with SC-42, focus your evaluation on whether the vendor has identified environments where sensor restrictions apply and whether those restrictions are enforced through documented procedures and technical controls.

Request the vendor’s system and communications protection policy and verify that it addresses sensor-capable devices specifically, not just general device management. Ask for a documented list of designated facilities or areas where sensor restrictions apply, along with the rationale for each designation.

Evaluate the vendor’s notification mechanism by requesting evidence that affected users receive explicit indication when sensors are active. This evidence should include screenshots, system configuration documentation, or user interface specifications showing how notifications are delivered. A vendor who can only point to a policy document without demonstrating the technical implementation is a red flag.

Ask targeted questionnaire questions to probe the depth of their implementation. These questions should cover how the vendor identifies and catalogs sensor-capable devices, what technical controls enforce sensor restrictions in designated areas, how exceptions are approved and documented, and how the vendor verifies that notification mechanisms function correctly.

Review the vendor’s audit records for sensor-related incidents or findings. Look for evidence of periodic testing, including physical verification that device restrictions are enforced at facility entry points. Vendors operating in environments with heightened IoT device proliferation should demonstrate awareness of the expanding sensor landscape beyond traditional smartphones and tablets.

Watch for common vendor gaps including policies that address “mobile devices” generically without acknowledging the full range of environmental sensors, notification mechanisms that exist in documentation but aren’t implemented in production systems, and exception processes that lack formal approval workflows.

Evidence examples

Evidence TypeExample Artifact
Sensor restriction policySystem and communications protection policy defining designated facilities, prohibited device types, and exception approval workflows
Access control proceduresProcedures for enforcing device restrictions at facility entry points, including visitor device handling and storage protocols
Designated area inventoryDocumented list of facilities and areas where sensor-equipped devices are restricted, with classification justification for each
Sensor notification configurationSystem design documentation and configuration settings showing how sensor activation indicators are delivered to designated users
Device management recordsMDM platform configuration exports showing geofenced sensor restrictions, enrolled device inventory, and policy enforcement status
Exception authorization recordsApproved exception requests documenting authorized sensor use, approving authority, scope limitations, and review dates
Audit and review evidenceSystem audit records from periodic reviews verifying that sensor restrictions remain enforced and notification mechanisms function correctly
Privacy and security plansSystem security plan and privacy plan sections addressing sensor capability controls, designated user groups, and notification requirements

Cross-framework mapping

No applicable cross-framework mappings have been configured for this control.

  • SC-15 — Collaborative Computing Devices and Applications: SC-15 governs the management of collaborative computing devices such as networked cameras, microphones, and video conferencing systems, complementing SC-42 by addressing sensor capabilities that are integrated into shared communication platforms rather than individual mobile devices.

Frequently asked questions

What is NIST SP 800-53 SC-42?

SC-42 is the NIST SP 800-53 control that requires organizations to prohibit or restrict devices with environmental sensing capabilities, including microphones, cameras, GPS receivers, and accelerometers, in designated facilities and to notify users when sensors are active. The control targets the risk of covert data collection through sensors embedded in mobile phones, tablets, and similar devices. It applies at the system level and spans both organizational and vendor environments.

What happens if SC-42 is not implemented?

Without SC-42, organizations have no documented mechanism to prevent covert environmental data collection through device sensors in sensitive areas. Auditors assessing the System and Communications Protection family will flag the absence of sensor restriction policies, designated area inventories, and user notification procedures as findings. The resulting compliance gap can delay authorization decisions and introduce risk to any system operating in environments where sensitive conversations or classified information are present.

How do you audit SC-42?

Auditing SC-42 starts with reviewing the system and communications protection policy for explicit provisions governing sensor-equipped device restrictions and sensor activation notifications. Auditors verify that designated facilities are inventoried, that technical enforcement mechanisms like MDM geofencing or physical device storage are operational, and that notification indicators function as documented. Evidence collection should include configuration exports, access control logs for designated areas, exception authorization records, and interview responses from designated user groups confirming they receive explicit sensor use indications.

Does SC-42 apply to IoT devices?

The supplemental guidance for SC-42 focuses on mobile devices such as smartphones and tablets, but the underlying principle extends to any system component with environmental sensing capabilities. IoT devices equipped with microphones, cameras, temperature sensors, or motion detectors in organizational facilities fall within the spirit of the control, particularly when those devices can be activated remotely. Organizations operating in environments with significant IoT deployments should address these devices in their sensor restriction policies and designated area inventories.

Experience superior visibility and a simpler approach to cyber risk management