NIST 800-171 Controls · System and Communications Protection
SC.2.012 — Prohibit Remote Activation of Collaborative Devices
Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.
What SC.2.012 means in plain English
Webcams and microphones on computers in areas where CUI is discussed should not be remotely activatable by anyone — not by IT staff, not by a hacker. Disable remote camera and mic activation features. When a webcam is active, there should be a visible indicator light so people in the room know they could be recorded. For conference room speakerphones and webcams, unplug or cover them when not in a meeting. This prevents eavesdropping on sensitive conversations.
The assessment question
“Are collaborative computing devices (webcams, microphones, speakerphones) protected against remote activation, and do they provide visible or audible indicators when active?”
How to implement SC.2.012
- Verify all laptops have a physical webcam indicator light (most modern laptops do). For external webcams without indicator lights, use a physical webcam cover slide (~$5 for a pack).
- In Windows, disable remote access to camera and microphone: Settings > Privacy > Camera and Microphone, disable access for apps that do not need it.
- For conference room equipment, establish a procedure to disconnect or power off webcams and speakerphones when not in active use. A simple power strip with an on/off switch works well.
- Implement a Group Policy to restrict which applications can access the camera and microphone on CUI workstations.
Evidence your assessor will ask for
- Windows Privacy settings screenshots showing camera and microphone access restrictions
- Photo evidence of webcam covers or indicator lights on workstations in CUI areas
- Procedure document for conference room device management (disconnect when not in use)
- Group Policy configuration restricting camera and microphone access
Does AI prompt monitoring help with this control? Honestly, no.
SC.2.012 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More System and Communications Protection controls
Monitor and Protect Communications at Boundaries
SC.1.005Implement Subnetworks for Public Components
SC.2.002Employ Effective Security Architecture
SC.2.003Separate User and System Management Functionality
SC.2.004Prevent Unauthorized Info Transfer via Shared Resources
SC.2.006Deny Network Traffic by Default
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.