03.01: Access Control
Controls
03.01.01: Account Management
Define the types of system accounts allowed and prohibited. Create, enable, modify, disable, and remove system accounts in accordance with policy, procedures, prerequisites, and criteria. Specify: Authorized users of the system, Group and role membership, and Access authorizations (i.e., privileges) for each account. Authorize access to the system based on: A valid access authorization and…
03.01.02: Access Enforcement
Enforce approved authorizations for logical access to CUI and system resources in accordance with applicable access control policies.
03.01.03: Information Flow Enforcement
Enforce approved authorizations for controlling the flow of CUI within the system and between connected systems.
03.01.04: Separation of Duties
Identify the duties of individuals requiring separation. Define system access authorizations to support separation of duties.
03.01.05: Least Privilege
Allow only authorized system access for users (or processes acting on behalf of users) that is necessary to accomplish assigned organizational tasks. Authorize access to [Assignment: organization-defined security functions] and [Assignment: organization-defined security-relevant information]. Review the privileges assigned to roles or classes of users [Assignment: organization-defined frequency] to validate the need for such privileges. Reassign…
03.01.06: Least Privilege — Privileged Accounts
Restrict privileged accounts on the system to [Assignment: organization-defined personnel or roles].. Require that users (or roles) with privileged accounts use non-privileged accounts when accessing non-security functions or non-security information.
03.01.07: Least Privilege — Privileged Functions
Prevent non-privileged users from executing privileged functions. Log the execution of privileged functions.
03.01.08: Unsuccessful Logon Attempts
Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]. Automatically [Selection (one or more): lock the account or node for an [Assignment: organization-defined time period]; lock the account or node until released by an administrator; delay next logon prompt; notify system administrator; take other…
03.01.09: System Use Notification
Display a system use notification message with privacy and security notices consistent with applicable CUI rules before granting access to the system.
03.01.10: Device Lock
Prevent access to the system by [Selection (one or more): initiating a device lock after [Assignment: organization-defined time period] of inactivity; requiring the user to initiate a device lock before leaving the system unattended]. Retain the device lock until the user reestablishes access using established identification and authentication procedures. Conceal, via the device lock, information…
03.01.11: Session Termination
Terminate a user session automatically after [Assignment: organization-defined conditions or trigger events requiring session disconnect].
03.01.12: Remote Access
Establish usage restrictions, configuration requirements, and connection requirements for each type of allowable remote system access. Authorize each type of remote system access prior to establishing such connections. Route remote access to the system through authorized and managed access control points. Authorize the remote execution of privileged commands and remote access to security-relevant information.
03.01.16: Wireless Access
Establish usage restrictions, configuration requirements, and connection requirements for each type of wireless access to the system. Authorize each type of wireless access to the system prior to establishing such connections. Disable, when not intended for use, wireless networking capabilities prior to issuance and deployment. Protect wireless access to the system using authentication and encryption.
03.01.18: Access Control for Mobile Devices
Establish usage restrictions, configuration requirements, and connection requirements for mobile devices. Authorize the connection of mobile devices to the system. Implement full-device or container-based encryption to protect the confidentiality of CUI on mobile devices.
03.01.20: Use of External Systems
Prohibit the use of external systems unless the systems are specifically authorized. Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [Assignment: organization-defined security requirements]. Permit authorized individuals to use external systems to access the organizational system or to process,…
03.01.22: Publicly Accessible Content
Train authorized individuals to ensure that publicly accessible information does not contain CUI. Review the content on publicly accessible systems for CUI and remove such information, if discovered.