System Access Control

The new compliance requirement for businesses working with the DoD is Cybersecurity Maturity Model Certification (CMMC). The CMMC model is designed to protect the defense information in all DoD contracts and the defense information that the contractor may produce. The model consists of five levels, with each higher level incorporating increasing levels of security. The goal is for all 300,000 companies in the defense industrial base to be audited and certified compliant by the start of the Fiscal Year 2026. The CMMC compliance certification will be a baseline requirement; with the appropriate certification level, there will be access to contracts; without certification, a company will be deemed unqualified.
The CMMC model practices are spread across 17 domains, and depending on the level, the practice requirements range from Level 1 with 17 requirements to Level 5 with 171 requirements. Most organizations will be Level 1 or Level 3 with 130 requirements. Level 1, with its six domains and 17 practice requirements, is a good place to start, beginning with Access Control. It is important to understand that system security requires a proactive approach; a step in that direction is taking control and controlling access. In general terms, all of system security is about controlling access or what to do if there is a loss of access control. Within CMMC Level 1, there are four requirements in the Access Control domain. These are foundational requirements which, in some form, all other requirements are related.
The first practice in access control is to limit access to only authorized users, processes, or devices. Systems or things connected to the information system need to be controlled and restricted. Access to the system resources is limited by users, groups, and objects (these can be IoT devices). Each user, group, object (service accounts), or process must have a unique login; each user/process should be restricted to only the resources they need. This is constraining access to the system, and it is constraining access to system resources. Each user/process should have unique credentials aligned to their role(s), with the role allowing access. One of the principles in system security is the Principle of Least Privilege. The rule states that there should be no universal access and that all users and processes are to be restricted to only the applications and tools they need to do their job. This rule can only be met if each user is uniquely identified. This is a system setup function, where the system administrator will require a unique identifier for each system user and restricted access for all users, meaning no person has access to everything; access is restricted by role.
The second access control practice requirement is to limit system access to the types of transactions and functions authorized users can execute. This is restricting access to only what the user needs for their job or role. This can be accomplished as all users are uniquely identified. Since each user is unique, access can be limited to only the transactions and the system functions that the user is permitted to execute. This, too, is related to the Principle of Least Privilege, where users or system access is limited to the resources needed for their job. This means there is no universal access and no group access, meaning no one user or identity has access to all software and administrative rights. An implied requirement is that there should be at least two accounts, even for a sole computer user, one for a general user with access to applications and a second restricted to the administrative role with only access to administrative functions. This, too, is a setup function, where the system administrator sets up permissions for each unique user based on roles and then assigns a role. It is the role that allows access to applications and data.
The third practice is to verify and control connections and the use of external information systems. To meet this practice requirement first is establishing configuration management control over the system and setting a policy to restrict system access to only approved devices. Configuration management controls what is in the system and what is added or removed from the system. Configuration management should outline the rules that allow cell phones, tablets, computers to join or not the system. The goal is to control access to the information management system. Just as you would not allow a random person to enter and walk around your home, you do not want random users accessing your system.
The fourth practice in Level 1 Access Control controls the information posted or processed on publicly accessible information systems. This is a commonsense requirement; here, the goal is to prohibit the public disclosure of federal contract information. It is also the prohibition of the public disclosure of company-controlled information to include your company’s financial information, personnel information, etc. There are implied tasks needed to be completed to meet this practice. The information has to be identified as controlled information: federal contract information or company-controlled information. In addition, employees need instructions or a policy that outlines what actions are prohibited, like disclosing company financial information to the public.
Access Control is a foundation in terms of securing the company’s information management system. As with all tasks in the CMMC model, there are the specified tasks or practice requirements that need to be accomplished, and there are implied tasks that need to be performed before the primary task can be completed. These information management system fundamentals are basic cyber-hygiene. Level 1 basic cyber-hygiene is like physical hygiene, where one takes steps and precautions to keep healthy. These fundamentals ensure the confidentiality of your information, the integrity of data, and ensure the availability of your information management system.

171 Comply
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.