Access Control
Limit system access to authorized users, processes acting on behalf of authorized users, and devices.
Access control is the largest family and the one most assessments start with. It asks who and what may use your systems, what each of them may do once inside, how CUI is allowed to move, and how remote, wireless and mobile access are kept on a leash. Four of its requirements are also Level 1 practices, and seven carry the full five points.
- 3.1.1 Know who and what is allowed on your systems
- 3.1.2 Limit what each person can do once inside
- 3.1.3 Control where CUI is allowed to travel
- 3.1.4 Split duties so one person cannot do everything alone
- 3.1.5 Give people the least access they need
- 3.1.6 Do ordinary work from ordinary accounts
- 3.1.7 Stop and log privileged actions by non-admins
- 3.1.8 Lock accounts after repeated failed logins
- 3.1.9 Show a use notice at sign-in
- 3.1.10 Lock idle screens
- 3.1.11 End sessions automatically
- 3.1.12 Watch and control remote access
- 3.1.13 Encrypt remote access
- 3.1.14 Funnel remote access through known entry points
- 3.1.15 Approve remote admin work in advance
- 3.1.16 Approve wireless before it connects
- 3.1.17 Protect wireless with authentication and encryption
- 3.1.18 Control which mobile devices connect
- 3.1.19 Encrypt CUI on mobile devices
- 3.1.20 Verify and limit outside systems
- 3.1.21 Limit portable storage on outside systems
- 3.1.22 Review what goes on public sites