Access Control
Account management, access enforcement, least privilege, remote and wireless access, mobile devices, external systems, and public content. Rev. 3 consolidates six Rev. 2 remote-access and device requirements into broader parents.
Every active Rev. 3 requirement with its official title, a labeled independent summary, and the practices that genuinely support it — including the three families that are new in this revision.
Requirement identifiers and official language come from the primary NIST publication; every explanation, mapping, and caveat is independent analysis by this site, authored against the primary source and last updated 2026-08-06. A subject-matter-expert review pass has not yet been completed, and the content is labeled accordingly. Nothing here is a compliance determination, an assessment, or a substitute for your own analysis within your defined system boundary.
Account management, access enforcement, least privilege, remote and wireless access, mobile devices, external systems, and public content. Rev. 3 consolidates six Rev. 2 remote-access and device requirements into broader parents.
Security literacy for everyone and role-based training for people with security-relevant duties. Insider-threat awareness is folded into literacy training rather than standing alone.
Which events are logged, what each record contains, how logs are generated, reviewed, protected, and time-stamped — with record content and generation now explicit requirements rather than implications.
Baselines, settings, change control, impact analysis, least functionality, authorized-software-by-exception, and — new as standalone requirements — component inventory, information location, and configuration for high-risk travel.
Identifying and authenticating users and devices, multi-factor and replay-resistant authentication, and consolidated identifier, password, and authenticator management aligned to current federal guidance.
Incident handling, monitoring, reporting, testing — and, new as standalone requirements in Rev. 3, incident response training and a written incident response plan.
Controlled maintenance tools, authenticated and terminated nonlocal maintenance sessions, and supervised maintenance personnel. Routine perform-maintenance expectations from Rev. 2 were recategorized rather than carried forward.
Storage, access, sanitization, marking, and transport of media holding CUI, plus removable-media use and cryptographic protection of backups. Transport encryption folds into the transport requirement.
Screening before access, and deliberate handling of system access through terminations and transfers.
Physical access authorization, monitoring, and control — with visitor handling, access logs, and access devices consolidated into a single physical access control requirement, plus alternate work sites and transmission-line access.
Assessing risk, monitoring and scanning for vulnerabilities, and — new as a standalone requirement — responding to findings from assessments and monitoring.
Assessing control effectiveness, maintaining plans of action and milestones, continuous monitoring, and — new — information-exchange agreements. The system security plan moved to the new Planning family.
Boundary protection, deny-by-default networking, cryptographic protection, session and key management. Rev. 3 merges transmission and at-rest confidentiality into one requirement and retires several technology-specific items.
Flaw remediation, malicious code protection, advisories, and system monitoring — consolidated from seven Rev. 2 requirements — plus new information management and retention.
New family in Rev. 3: security policies and procedures, the system security plan, and rules of behavior. Governance documentation that Rev. 2 scattered or left implicit is now explicit.
New family in Rev. 3: security engineering principles, unsupported system components, and external system services. This is where technical-debt and third-party-service discipline get explicit requirement language.
New family in Rev. 3: a supply chain risk management plan, acquisition strategies and methods, and supply chain requirements and processes for the components and services the system depends on.
“Mapped” counts requirements with at least one genuine practice relationship. Families with low counts — personnel, physical, media — are not gaps in this site’s analysis: the campaign simply has no practice working that ground, and pretending otherwise would make every other mapping less trustworthy.
| Requirement | Family | Mapped practices |
|---|---|---|
| 03.01.01 Account Management | 03.01 Access Control | IT-02OT-01 |
| 03.01.02 Access Enforcement | 03.01 Access Control | OT-01 |
| 03.01.03 Information Flow Enforcement | 03.01 Access Control | IT-05 |
| 03.01.04 Separation of Duties | 03.01 Access Control | No mapped practice |
| 03.01.05 Least Privilege | 03.01 Access Control | OT-01 |
| 03.01.06 Least Privilege — Privileged Accounts | 03.01 Access Control | OT-01 |
| 03.01.07 Least Privilege — Privileged Functions | 03.01 Access Control | No mapped practice |
| 03.01.08 Unsuccessful Logon Attempts | 03.01 Access Control | No mapped practice |
| 03.01.09 System Use Notification | 03.01 Access Control | No mapped practice |
| 03.01.10 Device Lock | 03.01 Access Control | No mapped practice |
| 03.01.11 Session Termination | 03.01 Access Control | No mapped practice |
| 03.01.12 Remote Access | 03.01 Access Control | IT-01OT-06 |
| 03.01.16 Wireless Access | 03.01 Access Control | No mapped practice |
| 03.01.18 Access Control for Mobile Devices | 03.01 Access Control | No mapped practice |
| 03.01.20 Use of External Systems | 03.01 Access Control | IT-08 |
| 03.01.22 Publicly Accessible Content | 03.01 Access Control | No mapped practice |
| 03.02.01 Literacy Training and Awareness | 03.02 Awareness and Training | IT-10 |
| 03.02.02 Role-Based Training | 03.02 Awareness and Training | IT-10 |
| 03.03.01 Event Logging | 03.03 Audit and Accountability | No mapped practice |
| 03.03.02 Audit Record Content | 03.03 Audit and Accountability | No mapped practice |
| 03.03.03 Audit Record Generation | 03.03 Audit and Accountability | No mapped practice |
| 03.03.04 Response to Audit Logging Process Failures | 03.03 Audit and Accountability | No mapped practice |
| 03.03.05 Audit Record Review, Analysis, and Reporting | 03.03 Audit and Accountability | OT-07 |
| 03.03.06 Audit Record Reduction and Report Generation | 03.03 Audit and Accountability | No mapped practice |
| 03.03.07 Time Stamps | 03.03 Audit and Accountability | No mapped practice |
| 03.03.08 Protection of Audit Information | 03.03 Audit and Accountability | No mapped practice |
| 03.04.01 Baseline Configuration | 03.04 Configuration Management | IT-02 |
| 03.04.02 Configuration Settings | 03.04 Configuration Management | IT-04 |
| 03.04.03 Configuration Change Control | 03.04 Configuration Management | OT-10 |
| 03.04.04 Impact Analyses | 03.04 Configuration Management | OT-10 |
| 03.04.05 Access Restrictions for Change | 03.04 Configuration Management | OT-10 |
| 03.04.06 Least Functionality | 03.04 Configuration Management | IT-03 |
| 03.04.08 Authorized Software — Allow by Exception | 03.04 Configuration Management | No mapped practice |
| 03.04.10 System Component Inventory | 03.04 Configuration Management | IT-02OT-02 |
| 03.04.11 Information Location | 03.04 Configuration Management | IT-08 |
| 03.04.12 System and Component Configuration for High-Risk Areas | 03.04 Configuration Management | No mapped practice |
| 03.05.01 User Identification, Authentication, and Re-Authentication | 03.05 Identification and Authentication | IT-01 |
| 03.05.02 Device Identification and Authentication | 03.05 Identification and Authentication | No mapped practice |
| 03.05.03 Multi-Factor Authentication | 03.05 Identification and Authentication | IT-01 |
| 03.05.04 Replay-Resistant Authentication | 03.05 Identification and Authentication | IT-01 |
| 03.05.05 Identifier Management | 03.05 Identification and Authentication | IT-02 |
| 03.05.07 Password Management | 03.05 Identification and Authentication | No mapped practice |
| 03.05.11 Authentication Feedback | 03.05 Identification and Authentication | No mapped practice |
| 03.05.12 Authenticator Management | 03.05 Identification and Authentication | IT-01 |
| 03.06.01 Incident Handling | 03.06 Incident Response | OT-04IT-09 |
| 03.06.02 Incident Monitoring, Reporting, and Response Assistance | 03.06 Incident Response | OT-04 |
| 03.06.03 Incident Response Testing | 03.06 Incident Response | OT-04 |
| 03.06.04 Incident Response Training | 03.06 Incident Response | No mapped practice |
| 03.06.05 Incident Response Plan | 03.06 Incident Response | OT-04 |
| 03.07.04 Maintenance Tools | 03.07 Maintenance | No mapped practice |
| 03.07.05 Nonlocal Maintenance | 03.07 Maintenance | OT-06IT-01 |
| 03.07.06 Maintenance Personnel | 03.07 Maintenance | No mapped practice |
| 03.08.01 Media Storage | 03.08 Media Protection | No mapped practice |
| 03.08.02 Media Access | 03.08 Media Protection | No mapped practice |
| 03.08.03 Media Sanitization | 03.08 Media Protection | No mapped practice |
| 03.08.04 Media Marking | 03.08 Media Protection | No mapped practice |
| 03.08.05 Media Transport | 03.08 Media Protection | No mapped practice |
| 03.08.07 Media Use | 03.08 Media Protection | No mapped practice |
| 03.08.09 System Backup — Cryptographic Protection | 03.08 Media Protection | IT-09OT-08 |
| 03.09.01 Personnel Screening | 03.09 Personnel Security | No mapped practice |
| 03.09.02 Personnel Termination and Transfer | 03.09 Personnel Security | No mapped practice |
| 03.10.01 Physical Access Authorizations | 03.10 Physical Protection | No mapped practice |
| 03.10.02 Monitoring Physical Access | 03.10 Physical Protection | No mapped practice |
| 03.10.06 Alternate Work Site | 03.10 Physical Protection | No mapped practice |
| 03.10.07 Physical Access Control | 03.10 Physical Protection | No mapped practice |
| 03.10.08 Access Control for Transmission | 03.10 Physical Protection | No mapped practice |
| 03.11.01 Risk Assessment | 03.11 Risk Assessment | IT-06 |
| 03.11.02 Vulnerability Monitoring and Scanning | 03.11 Risk Assessment | IT-06OT-05 |
| 03.11.04 Risk Response | 03.11 Risk Assessment | IT-06 |
| 03.12.01 Security Assessment | 03.12 Security Assessment and Monitoring | No mapped practice |
| 03.12.02 Plan of Action and Milestones | 03.12 Security Assessment and Monitoring | IT-06 |
| 03.12.03 Continuous Monitoring | 03.12 Security Assessment and Monitoring | No mapped practice |
| 03.12.05 Information Exchange | 03.12 Security Assessment and Monitoring | No mapped practice |
| 03.13.01 Boundary Protection | 03.13 System and Communications Protection | IT-05OT-03 |
| 03.13.04 Information in Shared System Resources | 03.13 System and Communications Protection | No mapped practice |
| 03.13.06 Network Communications — Deny by Default, Allow by Exception | 03.13 System and Communications Protection | IT-05OT-03 |
| 03.13.08 Transmission and Storage Confidentiality | 03.13 System and Communications Protection | IT-08 |
| 03.13.09 Network Disconnect | 03.13 System and Communications Protection | No mapped practice |
| 03.13.10 Cryptographic Key Establishment and Management | 03.13 System and Communications Protection | No mapped practice |
| 03.13.11 Cryptographic Protection | 03.13 System and Communications Protection | No mapped practice |
| 03.13.12 Collaborative Computing Devices and Applications | 03.13 System and Communications Protection | No mapped practice |
| 03.13.13 Mobile Code | 03.13 System and Communications Protection | No mapped practice |
| 03.13.15 Session Authenticity | 03.13 System and Communications Protection | No mapped practice |
| 03.14.01 Flaw Remediation | 03.14 System and Information Integrity | IT-06OT-05 |
| 03.14.02 Malicious Code Protection | 03.14 System and Information Integrity | No mapped practice |
| 03.14.03 Security Alerts, Advisories, and Directives | 03.14 System and Information Integrity | No mapped practice |
| 03.14.06 System Monitoring | 03.14 System and Information Integrity | OT-07 |
| 03.14.08 Information Management and Retention | 03.14 System and Information Integrity | IT-08 |
| 03.15.01 Policy and Procedures | 03.15 Planning | No mapped practice |
| 03.15.02 System Security Plan | 03.15 Planning | IT-02 |
| 03.15.03 Rules of Behavior | 03.15 Planning | No mapped practice |
| 03.16.01 Security Engineering Principles | 03.16 System and Services Acquisition | IT-07IT-04 |
| 03.16.02 Unsupported System Components | 03.16 System and Services Acquisition | IT-03 |
| 03.16.03 External System Services | 03.16 System and Services Acquisition | IT-04 |
| 03.17.01 Supply Chain Risk Management Plan | 03.17 Supply Chain Risk Management | OT-09 |
| 03.17.02 Acquisition Strategies, Tools, and Methods | 03.17 Supply Chain Risk Management | OT-09 |
| 03.17.03 Supply Chain Requirements and Processes | 03.17 Supply Chain Risk Management | OT-09 |
Filtering happens in this browser — nothing you type is sent anywhere. A requirement without a mapped practice is a deliberate editorial decision, not an omission: the campaign’s twenty practices do not cover every requirement, and this site does not manufacture coverage.
| Relationship type | Mappings | Meaning |
|---|---|---|
| Direct implementation support | 15 | The practice's core activity works on the substance of the requirement. Implementing the practice well advances this requirement directly — it still does not, by itself, satisfy it. |
| Partial implementation support | 29 | The practice advances part of the requirement's scope; other parts are untouched by it and need separate work. |
| Operational support | 2 | The practice keeps the capability the requirement depends on running day to day, rather than establishing it. |
| Governance support | 1 | The practice contributes ownership, review cadence, or decision records that the requirement's implementation relies on. |
| Evidence support | 2 | The practice's normal operation produces records relevant to demonstrating this requirement; it does not implement the requirement itself. |
| Dependency | 1 | The practice is a prerequisite that makes implementing the requirement realistic — absent it, work on the requirement is built on sand. |
| Contextual relationship | 7 | The practice informs or constrains how an organization approaches the requirement without acting on its substance. |