Practices
Showing 18 of 18 sampled practices
Authorized Access Control
Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
Evidence cheat sheet
- Access control policy (signed)
- Account provisioning workflow export
- Quarterly access review report
Implementation status
Finding: MET · Scoring impact reflected in the sandbox score above.
Framework crosswalk
Every mapped control that matches evidence attached toAC.L2-3.1.1inherits its status automatically. Click a row to open the mapped control detail.
| Framework | Control | Match driven by | Status |
|---|---|---|---|
| NIST 800-53 | AC-2 Account Management Theme: Access Control | Inherited | |
| NIST 800-171 | 3.1.1 Authorized Access Control Theme: Access Control | Inherited | |
| ISO 27001 | A.5.15 Access control Theme: Access Control | Inherited | |
| SOC 2 | CC6.1 Logical Access Security Theme: Access Control | Inherited | |
| HIPAA | §164.308(a)(4) Information Access Management Theme: Access Control | Inherited | |
| PCI DSS 4.0 | 7.2 Access assigned based on need Theme: Access Control | Inherited |
Answer once, satisfy many: in the full product, uploading an artifact here auto-attaches it to every mapped control across frameworks.
POA&M preview
Auto-populated from gaps and in-progress items (8)
- Complete evidenceAC.L2-3.1.20In progressExternal Connections
- Complete evidenceAU.L2-3.3.1In progressSystem Auditing
- RemediateAU.L2-3.3.5GapAudit Correlation
- Complete evidenceIR.L2-3.6.1In progressIncident Handling
- RemediateMA.L2-3.7.5GapNonlocal Maintenance
- Complete evidenceRA.L2-3.11.1In progressRisk Assessments
- Complete evidenceCA.L2-3.12.1In progressSecurity Control Assessment
- Complete evidenceSC.L2-3.13.11In progressCUI Encryption
Ready to run this on your real environment?
Load all 110 practices, attach real evidence, and generate an audit-grade SSP, SAR, and POA&M package for your C3PAO.