Only approved people, processes, and devices can access your CUI systems.
What it actually means
This is the front door. Every account, service, and device that can reach your CUI environment must be one you deliberately approved — and you must be able to show the list. In practice that means a central identity provider, a documented request-and-approval step before access is granted, and only managed/enrolled devices allowed to connect.
Pass or fail — an assessor needs a "yes" to each
- There is an authoritative list of authorized users, processes (service accounts), and devices for the CUI environment.
- Access is granted only after a documented request and approval.
- Only approved/enrolled devices can connect; unknown devices are blocked.
- The authorized list is reviewed periodically and reconciled against HR/onboarding.
What to have ready
- Access-control policy + the authorized-user/device list
- Screenshots of the identity provider (e.g., Entra ID) showing accounts and conditional-access/device rules
- A sample approved access request
- Device-enrollment (MDM) inventory
Where teams trip up
- Shared or generic logins ('frontdesk', 'admin') that aren't tied to a person
- No record of who approved access, or a stale user list
- Personal/unmanaged devices able to reach CUI
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
3.1.2 — Once they're in, this limits what they can do3.5.1 — You can't authorize identities you haven't uniquely identified3.5.2 — Authentication is how 'authorized' gets enforced
More in Access Control (3.1)
3.1.2 — Limit what users can do3.1.3 — Control the flow of CUI3.1.4 — Separate duties3.1.5 — Least privilege (especially for admins)3.1.6 — Use non-privileged accounts for routine work3.1.7 — Restrict and log privileged functions3.1.8 — Limit failed logons3.1.9 — Show privacy and security notices3.1.10 — Lock idle screens3.1.11 — End sessions automatically3.1.12 — Monitor and control remote access3.1.13 — Encrypt remote access sessions3.1.14 — Funnel remote access through managed points3.1.15 — Authorize privileged remote actions3.1.16 — Authorize wireless access first3.1.17 — Protect wireless with authentication + encryption3.1.18 — Control mobile device connections3.1.19 — Encrypt CUI on mobile devices3.1.20 — Control connections to external systems3.1.21 — Limit portable storage on external systems3.1.22 — Control what goes on public systems