3.13 System & Communications Protection1 ptPOA&M-eligible

3.13.3 — Separate user and admin functions

Separate user functionality from system management functionality.

Keep the controls that run the system away from the things ordinary users touch.

What it actually means

Administrative and management functions — admin consoles, management interfaces, server back-ends — should be separated from the user-facing side of a system. In practice that means admins use separate admin accounts and dedicated management interfaces, and ordinary users can't reach management functions. This limits the blast radius if a user account is compromised.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in System & Communications Protection (3.13)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.