CMMC Practice Number: AC.L1-3.1.22
CMMC Level: 1 CMMC Domain: Access Control (AC)
Practice Summary:
Control information posted or processed on publicly accessible information systems
Contents:
CMMC Practice Implementation |
Assessment Objectives
Determine if:
[a] individuals authorized to post or process information on publicly accessible systems are identified;
[b] procedures to ensure FCI is not posted or processed on publicly accessible systems are identified;
[c] a review process is in place prior to posting of any content to publicly accessible systems;
[d] content on publicly accessible systems is reviewed to ensure that it does not include FCI; and
[e] mechanisms are in place to remove and address improper posting of FCI.
Practice Clarification (DOD, CMU)
Do not allow FCI to become public – always safeguard the confidentiality of FCI by controlling the posting of FCI on company-controlled websites or public forums, and the exposure of FCI in public presentations or on public displays [d]. It is important to know which users are allowed to publish information on publicly accessible systems, like your company website, and implement a review process before posting such information [a,c]. If FCI is discovered on a publicly accessible system, procedures should be in place to remove that information and alert the appropriate parties [e].
Example
Your company decides to start issuing press releases about its projects in an effort to reach more potential customers. Your company receives FCI from the government as part of its DoD contract. Because you recognize the need to manage controlled information, including FCI, you meet with the employees who write the releases and post information to establish a review process [c]. It is decided that you will review press releases for FCI before posting it on the company website [a,d]. Only certain employees will be authorized to post to the website [a].
Potential Assessment Considerations
• Does information on externally facing systems (e.g., publicly accessible) have a documented approval chain for public release [c]?
Where To Look
- Access control policy
- procedures addressing publicly accessible content
- system security plan
- list of users authorized to post publicly accessible content on organizational systems
- training materials and/or records
- records of publicly accessible information reviews
- records of response to nonpublic information on public websites
- system audit logs and records
- security awareness training records
- other relevant documents or records
Who To Talk To
- Personnel with responsibilities for managing publicly accessible information posted on organizational systems
- personnel with information security responsibilities
Perform Test On
- Mechanisms implementing management of publicly accessible content
Additional Information
Improper use of the company’s proprietary information can damage the company. Improper use of CUI could cause damage to the government and/or its employees.
This requirement addresses systems that are controlled by the company and accessible to the public, typically without identification or authentication. The posting of information on non- organization information systems is covered by company policy.
DOD uses a variety of markings to identify CUI, identified in DOD Manual 5200.01 Vol 4, which will be updated as the NARA CUI rule (32 CFR 2002) is implemented. The most common form of DOD CUI held by contractors is Controlled Technical Information, which is marked with Distribution Statements B-F. Other DOD information may be marked as ‘For Official Use Only’ – which may or may not be CUI, and the contracting officer should be consulted if this marking is encountered to determine if it is DOD CUI.
CMMC Practice Background and References (DOD, CMU) |
Practice Discussion:
DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2
In accordance with laws, Executive Orders, directives, policies, regulations, or standards, the public is not authorized access to nonpublic information (e.g., information protected under the Privacy Act, CUI, and proprietary information). This requirement addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication. Individuals authorized to post CUI onto publicly accessible systems are designated. The content of information is reviewed prior to posting onto publicly accessible systems to ensure that nonpublic information is not included.
CMMC References:
· FAR Clause 52.204-21 b.1.iv
· NIST SP 800-171 Rev 1 3.1.22
· NIST SP 800-53 Rev 4 AC-22