03.01: Access Control

Controls

03.01.01: Account Management

Define the types of system accounts allowed and prohibited. Create, enable, modify, disable, and remove system accounts in accordance with policy, procedures, prerequisites, and criteria. Specify: Authorized users of the system, Group and role membership, and Access authorizations (i.e., privileges) for each account. Authorize access to the system based on: A valid access authorization and…

03.01.02: Access Enforcement

Enforce approved authorizations for logical access to CUI and system resources in accordance with applicable access control policies.

03.01.04: Separation of Duties

Identify the duties of individuals requiring separation. Define system access authorizations to support separation of duties.

03.01.05: Least Privilege

Allow only authorized system access for users (or processes acting on behalf of users) that is necessary to accomplish assigned organizational tasks. Authorize access to [Assignment: organization-defined security functions] and [Assignment: organization-defined security-relevant information]. Review the privileges assigned to roles or classes of users [Assignment: organization-defined frequency] to validate the need for such privileges. Reassign…

03.01.06: Least Privilege — Privileged Accounts

Restrict privileged accounts on the system to [Assignment: organization-defined personnel or roles].. Require that users (or roles) with privileged accounts use non-privileged accounts when accessing non-security functions or non-security information.

03.01.08: Unsuccessful Logon Attempts

Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]. Automatically [Selection (one or more): lock the account or node for an [Assignment: organization-defined time period]; lock the account or node until released by an administrator; delay next logon prompt; notify system administrator; take other…

03.01.09: System Use Notification

Display a system use notification message with privacy and security notices consistent with applicable CUI rules before granting access to the system.

03.01.10: Device Lock

Prevent access to the system by [Selection (one or more): initiating a device lock after [Assignment: organization-defined time period] of inactivity; requiring the user to initiate a device lock before leaving the system unattended]. Retain the device lock until the user reestablishes access using established identification and authentication procedures. Conceal, via the device lock, information…

03.01.11: Session Termination

Terminate a user session automatically after [Assignment: organization-defined conditions or trigger events requiring session disconnect].

03.01.12: Remote Access

Establish usage restrictions, configuration requirements, and connection requirements for each type of allowable remote system access. Authorize each type of remote system access prior to establishing such connections. Route remote access to the system through authorized and managed access control points. Authorize the remote execution of privileged commands and remote access to security-relevant information.

03.01.16: Wireless Access

Establish usage restrictions, configuration requirements, and connection requirements for each type of wireless access to the system. Authorize each type of wireless access to the system prior to establishing such connections. Disable, when not intended for use, wireless networking capabilities prior to issuance and deployment. Protect wireless access to the system using authentication and encryption.

03.01.18: Access Control for Mobile Devices

Establish usage restrictions, configuration requirements, and connection requirements for mobile devices. Authorize the connection of mobile devices to the system. Implement full-device or container-based encryption to protect the confidentiality of CUI on mobile devices.

03.01.20: Use of External Systems

Prohibit the use of external systems unless the systems are specifically authorized. Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [Assignment: organization-defined security requirements]. Permit authorized individuals to use external systems to access the organizational system or to process,…

03.01.22: Publicly Accessible Content

Train authorized individuals to ensure that publicly accessible information does not contain CUI. Review the content on publicly accessible systems for CUI and remove such information, if discovered.