to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

Access Control

Limit system access to authorized users, processes acting on behalf of authorized users, and devices.

Access control is the largest family and the one most assessments start with. It asks who and what may use your systems, what each of them may do once inside, how CUI is allowed to move, and how remote, wireless and mobile access are kept on a leash. Four of its requirements are also Level 1 practices, and seven carry the full five points.

  1. 3.1.1 Know who and what is allowed on your systems AC Level 1 5 pt
  2. 3.1.2 Limit what each person can do once inside AC Level 1 5 pt
  3. 3.1.3 Control where CUI is allowed to travel AC Level 2 1 pt
  4. 3.1.4 Split duties so one person cannot do everything alone AC Level 2 1 pt
  5. 3.1.5 Give people the least access they need AC Level 2 3 pt
  6. 3.1.6 Do ordinary work from ordinary accounts AC Level 2 1 pt
  7. 3.1.7 Stop and log privileged actions by non-admins AC Level 2 1 pt
  8. 3.1.8 Lock accounts after repeated failed logins AC Level 2 1 pt
  9. 3.1.9 Show a use notice at sign-in AC Level 2 1 pt
  10. 3.1.10 Lock idle screens AC Level 2 1 pt
  11. 3.1.11 End sessions automatically AC Level 2 1 pt
  12. 3.1.12 Watch and control remote access AC Level 2 5 pt
  13. 3.1.13 Encrypt remote access AC Level 2 5 pt
  14. 3.1.14 Funnel remote access through known entry points AC Level 2 1 pt
  15. 3.1.15 Approve remote admin work in advance AC Level 2 1 pt
  16. 3.1.16 Approve wireless before it connects AC Level 2 5 pt
  17. 3.1.17 Protect wireless with authentication and encryption AC Level 2 5 pt
  18. 3.1.18 Control which mobile devices connect AC Level 2 5 pt
  19. 3.1.19 Encrypt CUI on mobile devices AC Level 2 3 pt
  20. 3.1.20 Verify and limit outside systems AC Level 1 1 pt
  21. 3.1.21 Limit portable storage on outside systems AC Level 2 1 pt
  22. 3.1.22 Review what goes on public sites AC Level 1 1 pt