3.1 Access Control1 ptPOA&M-eligible

3.1.6 — Use non-privileged accounts for routine work

Use non-privileged accounts or roles when accessing nonsecurity functions.

Admins should do everyday tasks from a normal account, not their admin account.

What it actually means

People with admin rights should use a separate non-privileged account for routine work — email, web, documents — and only switch to the privileged account for actual admin tasks. This limits the damage if their everyday session is compromised.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Access Control (3.1)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.