3.14 System & Information Integrity3 pts

3.14.7 — Identify unauthorized use

Identify unauthorized use of organizational systems.

You can spot unauthorized use of your systems.

What it actually means

Beyond detecting outside attacks, you need to recognize unauthorized use — odd account activity, access at strange times, use outside someone's role. It leans on your logging, monitoring, and review working together.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in System & Information Integrity (3.14)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.