NIST SP 800-171 Rev 2 · 3.1 Access Control
3.1.5 Least privilege
Employ the principle of least privilege, including for specific security functions and privileged accounts.
- SPRS weight
- 3
- 3 points deducted from 110 when not implemented.
- CMMC level
- L2
- Level 2 only; not among the 17 Level 1 practices.
- Assessment objectives
- 4
- From NIST SP 800-171A, each one a “determine if” an assessor answers.
What an assessor checks
NIST SP 800-171A breaks 3.1.5 into 4 objectives. Every one has to be met for the requirement to be met; a partial answer scores as not implemented.
- [a]Determine if privileged accounts are identified.
- [b]Determine if access to privileged accounts is authorized in accordance with the principle of least privilege.
- [c]Determine if security functions are identified.
- [d]Determine if access to security functions is authorized in accordance with the principle of least privilege.
- Examine
- [SELECT FROM: Access control policy; procedures addressing account management; security plan; system design documentation; system configuration settings and associated documentation; list of active system accounts and the name of the individual associated with each account; list of conditions for group and role membership; notifications or records of recently transferred, separated, or terminated employees; list of recently disabled system accounts along with the name of the individual associated with each account; access authorization records; account management compliance reviews; system monitoring/audit records; other relevant documents or records; procedures addressing least privilege; list of security functions (deployed in hardware, software, and firmware) and security-relevant information for which access must be explicitly authorized; list of system-generated privileged accounts; list of system administration personnel].
- Interview
- [SELECT FROM: Personnel with account management responsibilities; system or network administrators; personnel with information security responsibilities; personnel with responsibilities for defining least privileges necessary to accomplish specified tasks].
- Test
- [SELECT FROM: Organizational processes for managing system accounts; mechanisms for implementing account management; mechanisms implementing least privilege functions; mechanisms prohibiting privileged access to the system].
If it is open: POA&M eligibility
Not POA&M-eligible: above the 1-point ceiling · 3 points deducted
Worth 3 points. No requirement over 1 point may appear on a Level 2 POA&M, so this has to be closed before the assessment.
A POA&M is only permitted at a score of 88 or above, and closes in one 180-day window. Check a full gap list or compute your score.
Where 3.1.5 maps
NIST SP 800-53 Rev 5
- AC-6 Least Privilege
NIST CSF 2.0
- Access is managed
SOC 2
No direct mapping.
Query it from your own tools
This page and the MacTech CMMC MCP server render the same dataset. Ask your assistant and it will answer from the methodology, not from memory.
lookup_control 3.1.5 get_assessment_objectives 3.1.5 generate_poam_entries ["3.1.5"]
Install the MCP server, free, no account.
From MacZine