NIST 800-171 · Access Control

Requirement 3.1.1

SPRS weight
SPRS weight: 5
POA&M eligibility
Not POA&M-eligible
Assessment objectives
6 assessment objectives

Official requirement text

Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.1.1[a]authorized users are identified.
  2. 3.1.1[b]processes acting on behalf of authorized users are identified.
  3. 3.1.1[c]devices (including other systems) authorized to connect to the system are identified.
  4. 3.1.1[d]system access is limited to authorized users.
  5. 3.1.1[e]system access is limited to processes acting on behalf of authorized users.
  6. 3.1.1[f]system access is limited to authorized devices (including other systems).

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.