Controls & assessment objectives
110 controls
- AC.L2-3.1.1AC · Access ControlLevel 2CMMC L2
Authorized Access Control [CUI Data]
Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
- 6objectives
- 1examples
- 0threads
- AC.L2-3.1.2AC · Access ControlLevel 2CMMC L2
Transaction & Function Control
Limit system access to the types of transactions and functions that authorized users are permitted to execute.
- 2objectives
- 1examples
- 0threads
- AC.L2-3.1.3AC · Access ControlLevel 2CMMC L2
Control CUI Flow
Control the flow of CUI in accordance with approved authorizations.
- 5objectives
- 1examples
- 0threads
- AC.L2-3.1.4AC · Access ControlLevel 2CMMC L2
Separation of Duties
Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
- 3objectives
- 1examples
- 0threads
- AC.L2-3.1.5AC · Access ControlLevel 2CMMC L2
Least Privilege
Employ the principle of least privilege, including for specific security functions and privileged accounts.
- 4objectives
- 1examples
- 0threads
- AC.L2-3.1.6AC · Access ControlLevel 2CMMC L2
Non-privileged Account Use
Use non-privileged accounts or roles when accessing nonsecurity functions.
- 2objectives
- 1examples
- 0threads
- AC.L2-3.1.7AC · Access ControlLevel 2CMMC L2
Privileged Functions
Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.
- 4objectives
- 1examples
- 0threads
- AC.L2-3.1.8AC · Access ControlLevel 2CMMC L2
Unsuccessful Logon Attempts
Limit unsuccessful logon attempts.
- 2objectives
- 1examples
- 0threads
- AC.L2-3.1.9AC · Access ControlLevel 2CMMC L2
Privacy & Security Notices
Provide privacy and security notices consistent with applicable CUI rules.
- 2objectives
- 1examples
- 0threads
- AC.L2-3.1.10AC · Access ControlLevel 2CMMC L2
Session Lock
Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
- 3objectives
- 1examples
- 0threads
- AC.L2-3.1.11AC · Access ControlLevel 2CMMC L2
Session Termination
Terminate (automatically) a user session after a defined condition.
- 2objectives
- 1examples
- 0threads
- AC.L2-3.1.12AC · Access ControlLevel 2CMMC L2
Control Remote Access
Monitor and control remote access sessions.
- 4objectives
- 1examples
- 0threads
- AC.L2-3.1.13AC · Access ControlLevel 2CMMC L2
Remote Access Confidentiality
Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
- 2objectives
- 1examples
- 0threads
- AC.L2-3.1.14AC · Access ControlLevel 2CMMC L2
Remote Access Routing
Route remote access via managed access control points.
- 2objectives
- 1examples
- 0threads
- AC.L2-3.1.15AC · Access ControlLevel 2CMMC L2
Privileged Remote Access
Authorize remote execution of privileged commands and remote access to security-relevant information.
- 4objectives
- 1examples
- 0threads
- AC.L2-3.1.16AC · Access ControlLevel 2CMMC L2
Wireless Access Authorization
Authorize wireless access prior to allowing such connections.
- 2objectives
- 1examples
- 0threads
- AC.L2-3.1.17AC · Access ControlLevel 2CMMC L2
Wireless Access Protection
Protect wireless access using authentication and encryption.
- 2objectives
- 1examples
- 0threads
- AC.L2-3.1.18AC · Access ControlLevel 2CMMC L2
Mobile Device Connection
Control connection of mobile devices.
- 3objectives
- 1examples
- 0threads
- AC.L2-3.1.19AC · Access ControlLevel 2CMMC L2
Encrypt CUI on Mobile
Encrypt CUI on mobile devices and mobile computing platforms.
- 2objectives
- 1examples
- 0threads
- AC.L2-3.1.20AC · Access ControlLevel 2CMMC L2
External Connections [CUI Data]
Verify and control/limit connections to and use of external systems.
- 6objectives
- 1examples
- 0threads
- AC.L2-3.1.21AC · Access ControlLevel 2CMMC L2
Portable Storage Use
Limit use of portable storage devices on external systems.
- 3objectives
- 1examples
- 0threads
- AC.L2-3.1.22AC · Access ControlLevel 2CMMC L2
Control Public Information [CUI Data]
Control CUI posted or processed on publicly accessible systems.
- 5objectives
- 1examples
- 0threads
- AT.L2-3.2.1AT · Awareness and TrainingLevel 2CMMC L2
Role-based Risk Awareness
Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.
- 4objectives
- 1examples
- 0threads
- AT.L2-3.2.2AT · Awareness and TrainingLevel 2CMMC L2
Role-based Training
Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.
- 3objectives
- 1examples
- 0threads
- AT.L2-3.2.3AT · Awareness and TrainingLevel 2CMMC L2
Insider Threat Awareness
Provide security awareness training on recognizing and reporting potential indicators of insider threat.
- 2objectives
- 1examples
- 0threads