Access Control
Limit system access to authorized users and processes.
Authorized Access Control
Limit system access to authorized users, processes acting on behalf of authorized users, and devices.
Transaction & Function Control
Limit system access to the types of transactions and functions that authorized users are permitted to execute.
Control CUI Flow
Control the flow of CUI in accordance with approved authorizations.
Separation of Duties
Separate duties of individuals to reduce the risk of malevolent activity without collusion.
Least Privilege
Employ the principle of least privilege, including for specific security functions and privileged accounts.
Non-Privileged Accounts
Use non-privileged accounts when accessing nonsecurity functions.
Privileged Functions
Prevent non-privileged users from executing privileged functions and capture execution of such functions in audit logs.
Unsuccessful Logon Attempts
Limit unsuccessful logon attempts.
Privacy and Security Notices
Provide privacy and security notices consistent with applicable CUI rules.
Session Lock
Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
Session Termination
Terminate user sessions automatically after a defined condition.
Remote Access Monitoring
Monitor and control remote access sessions.
Cryptographic Remote Access
Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
Routing Remote Access
Route remote access via managed access control points.
Privileged Remote Execution
Authorize remote execution of privileged commands and remote access to security-relevant information.
Wireless Access Authorization
Authorize wireless access prior to allowing such connections.
Wireless Protection
Protect wireless access using authentication and encryption.
Mobile Device Connection
Control connection of mobile devices.
Mobile Device Encryption
Encrypt CUI on mobile devices and mobile computing platforms.
External Connections
Verify and control/limit connections to and use of external systems.
Portable Storage Use
Limit use of portable storage devices on external systems.
Public Information Posting
Control CUI posted or processed on publicly accessible systems.