CMMC AC.4.025 - Review CUI Access

CMMC AC.4.025 - Review CUI Access

Requirement text: AC.4.025: Periodically review and update CUI program access permissions.

DISCUSSION FROM SOURCE: CMMC
Organizations must maintain the authorizations for access to CUI information on a regular
basis, considering whether existing authorizations are still needed or new authorization are
required, and update the authorizations accordingly. Reviews of access take into
consideration mission/business needs and maintain the organization’s implementation of
the principle of least privilege.

CMMC CLARIFICATION
Users must have organizational approval to read, write and process CUI associated with a
program, and the organization must maintain an authoritative list of who has been granted
access to CUI. Review and update ACLs and/or appropriate access methods periodically (as
determined by the organization, but at least annually) to maintain accurate permission sets
when employees' roles change.

Example
You manage IT for your organization. When a new employee joined the organization, they
were granted complete access to CUI for the project they were working on. A few months
later, their role changed when they are moved to a different project owned by the same
program manager but no longer requiring access to CUI. During the periodic review of the
access control configuration, you compare the results to the official permission baseline held
by the program manager. You determine that the employee should no longer have access to
CUI. You revoke the CUI access permissions of the user.

References
• CMMC
    • Related Articles

    • Access Control: SP 800-171 Security Family 3.1

      Access is the ability to make use of any system resource. Access control is the process of granting or denying requests to:       • use information,       • use information processing services, and       • enter company facilities.  System-based ...
    • CMMC AC.2.016 - Control CUI Flow

      Requirement text: AC.2.016: Control the flow of CUI in accordance with approved authorizations. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 Information flow control regulates where information can travel within a system and between systems ...
    • CMMC AC.2.015 - Use Managed Access Points

      Requirement text: AC.2.015: Route remote access via managed access control points. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 Routing remote access through managed access control points enhances explicit, organizational control over such ...
    • CMMC AC.2.013 - Control Remote Access

      Requirement text: AC.2.013: Monitor and control remote access sessions. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 Remote access is access to organizational systems by users (or processes acting on behalf of users) communicating through ...
    • CMMC Level 1 Overview - Basic Cyber Hygiene

      CMMC Level 1 l focuses on Federal Contract Information (FCI), which is defined as “information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the ...