3.1 Access Control5 ptsAlso Level 1

3.1.2 — Limit what users can do

Limit system access to the types of transactions and functions that authorized users are permitted to execute.

Users can only perform the transactions and functions their job requires.

What it actually means

Getting in the door isn't the same as having the run of the house. Each role should be able to do only what that job needs — least functionality, enforced through role-based access control in your identity provider and applications. The goal an assessor checks: permissions map to job duties, and they're documented.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Access Control (3.1)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.