NIST SP 800-171 & CMMC 2.0 3.1.2 Requirement:
Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
NIST SP 800-171 & CMMC 2.0 3.1.2 Requirement Explanation:
System users should only be granted access to the information and the account privileges they need to perform their job roles. This includes limiting personnel access to specific SharePoint sites, network drive folders, and devices such as servers. This also includes limiting administrative privileges to a select group of personnel with IT or security roles.
Example NIST SP 800-171 & CMMC 2.0 3.1.2 Implementation:
Only allow users to access the systems and information they need to complete their assigned work tasks. Review your user's current permissions and determine if they are inline with their job duties. If a user has more access than they need, revoke the excess access. Create user security groups to reflect the access requirements of your employees. Add your users to the appropriate group.
NIST SP 800-171 & CMMC 2.0 3.1.2 Scenario(s):
- Scenario 1:
Two new employees are scheduled to start next week Monday. One will be working in the HR department, the other will be an application developer. Alice, a system administrator creates their user accounts and adds each employee to a different user group. The new HR employee is added to the "HR" security group and the developer employee is added to the "Developers" security group. The security groups give the new employees access to a different set of file shares and other network resources. The HR employee will be able to access the file server used by the HR team but will not be able to access any other servers. The new developer will be able to access his development servers but not the HR file server. Both employees are only allowed access to authorized systems and both employees can complete their work.
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you