HomeControl Library › 3.1.22
3.1 Access Control1 ptAlso Level 1POA&M-eligible

3.1.22 — Control what goes on public systems

Control CUI posted or processed on publicly accessible systems.

Make sure no CUI ends up on your public website or public-facing systems.

What it actually means

Control CUI posted or processed on publicly accessible systems — make sure CUI never gets published to your public website or other public systems. Designate who can post public content and review it to ensure no CUI slips out. This is also a Level 1 (FCI) requirement.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

Also a Level 1 (FCI) requirement.

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library