AC.L2-3.1.1Authorized Access Control
Only the people, accounts and devices you have approved can reach these systems. Nothing gets in simply because it turned up on the network.
Limit system access to authorised users, to processes acting on behalf of authorised users, and to devices, including other systems.
Applies at level 1.
AC.L2-3.1.2Transaction & Function Control
Having an account is not the same as being able to do everything with it. Each person can only run the actions their job needs.
Limit system access to the types of transactions and functions that authorised users are permitted to execute.
Applies at level 1.
AC.L2-3.1.3Control CUI Flow
You have decided where this information is allowed to travel, and something stops it going somewhere you never approved.
Control the flow of controlled unclassified information within the system and between connected systems, according to approved authorisations.
Applies at level 2.
AC.L2-3.1.4Separation of Duties
No one person can start and finish a sensitive job alone. Splitting the steps means someone acting on their own cannot hide it.
Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
Applies at level 2.
AC.L2-3.1.5Least Privilege
People hold the least access that lets them do their job, and administrator rights go only to those who genuinely need them.
Employ the principle of least privilege, including for specific security functions and for privileged accounts.
Applies at level 2.
AC.L2-3.1.6Non-Privileged Account Use
Your administrators have an ordinary second account for email and everyday work, and save the powerful one for the tasks that need it.
Use non-privileged accounts or roles when accessing functions that are not security functions.
Applies at level 2.
AC.L2-3.1.7Privileged Functions
Ordinary accounts cannot run administrator commands, and when someone does run one it is recorded.
Prevent non-privileged users from executing privileged functions, and capture the execution of such functions in audit logs.
Applies at level 2.
AC.L2-3.1.8Unsuccessful Logon Attempts
After a set number of failed logins the account locks. Guessing passwords should not be something anyone can keep doing all night.
Limit unsuccessful logon attempts.
Applies at level 2.
AC.L2-3.1.9Privacy & Security Notices
People see a notice when they log in saying the system holds protected information and what is expected of them while they are in it.
Provide privacy and security notices consistent with the rules that apply to controlled unclassified information.
Applies at level 2.
AC.L2-3.1.10Session Lock
Screens lock themselves after a few minutes and hide what was on them, so an unattended desk is not an open door.
Use session lock with pattern-hiding displays to prevent access to and viewing of data after a period of inactivity.
Applies at level 2.
AC.L2-3.1.11Session Termination
Sessions end on their own after a set time or condition, rather than staying open until someone remembers to log out.
Terminate a user session automatically after a defined condition.
Applies at level 2.
AC.L2-3.1.12Control Remote Access
You know who is connecting from outside the office, when, and from where, and you could cut a session off if you had to.
Monitor and control remote access sessions.
Applies at level 2.
AC.L2-3.1.13Remote Access Confidentiality
Remote connections are encrypted, so someone sharing the coffee shop network cannot read what is going past.
Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
Applies at level 2.
AC.L2-3.1.14Remote Access Routing
Remote workers come in through one or two controlled entry points you watch, not through a different door on every server.
Route remote access through managed access control points.
Applies at level 2.
AC.L2-3.1.15Privileged Remote Access
Running administrator commands from outside the office is approved in advance, not something anyone can decide to do on the spot.
Authorise the remote execution of privileged commands and remote access to security-relevant information.
Applies at level 2.
AC.L2-3.1.16Wireless Access Authorization
Wireless networks are approved before they go live, so you know which ones exist rather than discovering one somebody plugged in.
Authorise wireless access before allowing such connections.
Applies at level 2.
AC.L2-3.1.17Wireless Access Protection
Your Wi-Fi asks who you are and encrypts what it carries. An open guest network must not be able to reach the protected systems.
Protect wireless access using authentication and encryption.
Applies at level 2.
AC.L2-3.1.18Mobile Device Connection
You decide which phones and tablets may connect, so an unknown device cannot simply join and start pulling data down.
Control the connection of mobile devices.
Applies at level 2.
AC.L2-3.1.19Encrypt CUI on Mobile
Protected information on phones, tablets and laptops is encrypted, so a device left in a taxi stays a lost device rather than a breach.
Encrypt controlled unclassified information held on mobile devices and mobile computing platforms.
Applies at level 2.
AC.L2-3.1.20External Connections
You know which outside services and personal machines can reach your systems, and you have set limits on what they are allowed to do.
Verify and control or limit connections to, and use of, external systems.
Applies at level 1.
AC.L2-3.1.21Portable Storage Use
Your USB sticks and drives are not for plugging into machines you do not control, and your team knows that is the rule.
Limit the use of portable storage devices on external systems.
Applies at level 2.
AC.L2-3.1.22Control Public Information
Someone checks what goes onto your website and social accounts, so protected information never gets published by accident.
Control controlled unclassified information posted on, or processed by, publicly accessible systems.
Applies at level 1.