AC.L2-3.1.1Authorized Access Control [CUI Data]
Allow only authorized users, approved processes, and permitted devices to access systems handling organizational information.
AC.L2-3.1.2Transaction & Function Control [CUI Data]
Restrict each authorized user to only the system transactions and functions approved for their role.
AC.L2-3.1.4Separation of Duties
Divide sensitive duties among separate people or roles so no individual can perform incompatible critical activities alone.
AC.L2-3.1.5Least Privilege
Grant users, processes, and privileged accounts only the access necessary to perform their authorized responsibilities.
AC.L2-3.1.6Non-Privileged Account Use
Require users to perform ordinary, nonsecurity work through non-privileged accounts or roles.
AC.L2-3.1.9Privacy & Security Notices
Display approved privacy and security notices before users access systems that handle CUI.
AC.L2-3.1.12Control Remote Access
Monitor remote access activity and enforce approved controls throughout each remote session.
AC.L2-3.1.13Remote Access Confidentiality
Protect the confidentiality of remote access sessions with approved cryptographic safeguards.
AC.L2-3.1.15Privileged Remote Access
Require explicit authorization before remotely executing privileged commands or accessing security-relevant information.
AC.L2-3.1.20External Connections [CUI Data]
Verify external systems meet defined security conditions, then restrict and monitor their connections and use.
AC.L2-3.1.22Control Public Information [CUI Data]
Review publicly accessible systems and prevent CUI from being posted or processed there without authorization.