03.01.01Account Management
Define the types of system accounts allowed and prohibited. Create, enable, modify, disable, and remove system accounts in accordance with policy, procedures, prerequisites, and criteria. Specify: Authorized users of the system, Group and role membership, and Access authorizations (i.e., privileges) for each account. Authorize access to the system based on: A valid access authorization and Intended system usage. Monitor the use of system accounts. Disable system accounts when: The accounts have expired, The accounts have been inactive for [Assignment: organization-defined], The accounts are no longer associated with a user or individual, The accounts are in violation of organizational policy, or Significant risks associated with individuals are discovered. Notify account managers and designated personnel or roles within: [Assignment: organization-defined] when accounts are no longer required. [Assignment: organization-defined] when users are terminated or transferred. [Assignment: organization-defined] when system usage or the need-to-know changes for an individual. Require that users log out of the system after [Assignment: organization-defined] of expected inactivity or when [Assignment: organization-defined].
03.01.02Access Enforcement
Enforce approved authorizations for logical access to CUI and system resources in accordance with applicable access control policies.
03.01.03Information Flow Enforcement
Enforce approved authorizations for controlling the flow of CUI within the system and between connected systems.
03.01.04Separation of Duties
Identify the duties of individuals requiring separation. Define system access authorizations to support separation of duties.
03.01.05Least Privilege
Allow only authorized system access for users (or processes acting on behalf of users) that is necessary to accomplish assigned organizational tasks. Authorize access to [Assignment: organization-defined] and [Assignment: organization-defined]. Review the privileges assigned to roles or classes of users [Assignment: organization-defined] to validate the need for such privileges. Reassign or remove privileges, as necessary.
03.01.06Least Privilege – Privileged Accounts
Restrict privileged accounts on the system to [Assignment: organization-defined].. Require that users (or roles) with privileged accounts use non-privileged accounts when accessing non-security functions or non-security information.
03.01.07Least Privilege – Privileged Functions
Prevent non-privileged users from executing privileged functions. Log the execution of privileged functions.
03.01.08Unsuccessful Logon Attempts
Enforce a limit of [Assignment: organization-defined] consecutive invalid logon attempts by a user during a [Assignment: organization-defined]. Automatically [Assignment: organization-defined] when the maximum number of unsuccessful attempts is exceeded.
03.01.09System Use Notification
Display a system use notification message with privacy and security notices consistent with applicable CUI rules before granting access to the system.
03.01.10Device Lock
Prevent access to the system by [Assignment: organization-defined]. Retain the device lock until the user reestablishes access using established identification and authentication procedures. Conceal, via the device lock, information previously visible on the display with a publicly viewable image.
03.01.11Session Termination
Terminate a user session automatically after [Assignment: organization-defined].
03.01.12Remote Access
Establish usage restrictions, configuration requirements, and connection requirements for each type of allowable remote system access. Authorize each type of remote system access prior to establishing such connections. Route remote access to the system through authorized and managed access control points. Authorize the remote execution of privileged commands and remote access to security-relevant information.
03.01.16Wireless Access
Establish usage restrictions, configuration requirements, and connection requirements for each type of wireless access to the system. Authorize each type of wireless access to the system prior to establishing such connections. Disable, when not intended for use, wireless networking capabilities prior to issuance and deployment. Protect wireless access to the system using authentication and encryption.
03.01.18Access Control for Mobile Devices
Establish usage restrictions, configuration requirements, and connection requirements for mobile devices. Authorize the connection of mobile devices to the system. Implement full-device or container-based encryption to protect the confidentiality of CUI on mobile devices.
03.01.20Use of External Systems
Prohibit the use of external systems unless the systems are specifically authorized. Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [Assignment: organization-defined]. Permit authorized individuals to use external systems to access the organizational system or to process, store, or transmit CUI only after: Verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied and Retaining approved system connection or processing agreements with the organizational entities hosting the external systems. Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems.
03.01.22Publicly Accessible Content
Train authorized individuals to ensure that publicly accessible information does not contain CUI. Review the content on publicly accessible systems for CUI and remove such information, if discovered.