HomeControl Library › 3.1.2
3.1 Access Control5 ptsAlso Level 1

3.1.2 — Limit what users can do

Limit system access to the types of transactions and functions that authorized users are permitted to execute.

Users can only perform the transactions and functions their job requires.

What it actually means

Getting in the door isn't the same as having the run of the house. Each role should be able to do only what that job needs — least functionality, enforced through role-based access control in your identity provider and applications. The goal an assessor checks: permissions map to job duties, and they're documented.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library