AC-3(11): Restrict Access to Specific Information Types

Control Family:

Access Control

CSF v1.1 References:

CSF v2.0 References:

Threats Addressed:

Baselines:

  • OT High (SP 800-82r3)
Info icon.

Control is new to this version of the control set.

Control Statement

Restrict access to data repositories containing [Assignment: organization-defined information types].

Supplemental Guidance

Restricting access to specific information is intended to provide flexibility regarding access control of specific information types within a system. For example, role-based access could be employed to allow access to only a specific type of personally identifiable information within a database rather than allowing access to the database in its entirety. Other examples include restricting access to cryptographic keys, authentication information, and selected system information.

OT Discussion

The organization identifies and restricts access to information that could impact the OT environment and accounts for information types that are sensitive, proprietary, contain trade secrets, or support safety functions.

OT Baseline Rationale

Rationale for adding to High baseline: The loss of availability, integrity, and confidentiality of certain types of information that reside on a high-impact OT system may result in severe or catastrophic adverse effects on operations, assets, or individuals, including severe degradation or loss of mission capability, major damage to organizational assets, or harm to individuals involving the loss of life or life-threatening injuries.