Users can only perform the transactions and functions their job requires.
What it actually means
Getting in the door isn't the same as having the run of the house. Each role should be able to do only what that job needs — least functionality, enforced through role-based access control in your identity provider and applications. The goal an assessor checks: permissions map to job duties, and they're documented.
Pass or fail — an assessor needs a "yes" to each
- Roles (or per-application permissions) are defined and mapped to job duties.
- Users are assigned the minimum permissions their role requires.
- Role definitions are documented and reviewed periodically.
What to have ready
- Role/permission matrix tied to job functions
- Identity-provider role assignments and app permission settings
- Evidence of periodic access review
Where teams trip up
- Everyone is an admin or has broad blanket access
- Permissions accrete over time and are never pruned
- No documentation of what each role is allowed to do
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
3.1.1 — Controls who gets in at all3.1.5 — Least privilege for admins/security functions specifically
More in Access Control (3.1)
3.1.1 — Limit who (and what) can get in3.1.3 — Control the flow of CUI3.1.4 — Separate duties3.1.5 — Least privilege (especially for admins)3.1.6 — Use non-privileged accounts for routine work3.1.7 — Restrict and log privileged functions3.1.8 — Limit failed logons3.1.9 — Show privacy and security notices3.1.10 — Lock idle screens3.1.11 — End sessions automatically3.1.12 — Monitor and control remote access3.1.13 — Encrypt remote access sessions3.1.14 — Funnel remote access through managed points3.1.15 — Authorize privileged remote actions3.1.16 — Authorize wireless access first3.1.17 — Protect wireless with authentication + encryption3.1.18 — Control mobile device connections3.1.19 — Encrypt CUI on mobile devices3.1.20 — Control connections to external systems3.1.21 — Limit portable storage on external systems3.1.22 — Control what goes on public systems