Answers 2025/2026
AC.L1-3.1.1[a] - ANSWERSauthorized users are identified.
AC.L1-3.1.1[b] - ANSWERSprocesses acting on behalf of authorized users are identified.
AC.L1-3.1.1[c] - ANSWERSdevices (and other systems) authorized to connect to the system are
identified.
AC.L1-3.1.1[d] - ANSWERSsystem access is limited to authorized users.
AC.L1-3.1.1[e] - ANSWERSsystem access is limited to processes acting on behalf of authorized
users.
AC.L1-3.1.1[f] - ANSWERSsystem access is limited to authorized devices (including other
systems).
AC.L1-3.1.2[a] - ANSWERSthe types of transactions and functions that authorized users are
permitted to execute are defined.
AC.L1-3.1.2[b] - ANSWERSsystem access is limited to the defined types of transactions and
functions for authorized users.
AC.L2-3.1.3[a] - ANSWERSinformation flow control policies are defined.
,AC.L2-3.1.3[b] - ANSWERSmethods and enforcement mechanisms for controlling the flow of CUI
are defined.
AC.L2-3.1.3[c] - ANSWERSdesignated sources and destinations (e.g., networks, individuals, and
devices) for CUI within the system and between interconnected systems are identified.
AC.L2-3.1.3[d] - ANSWERSauthorizations for controlling the flow of CUI are defined.
AC.L2-3.1.3[e] - ANSWERSapproved authorizations for controlling the flow of CUI are enforced.
AC.L2-3.1.4[a] - ANSWERSthe duties of individuals requiring separation are defined.
AC.L2-3.1.4[b] - ANSWERSresponsibilities for duties that require separation are assigned to
separate individuals.
AC.L2-3.1.4[c] - ANSWERSaccess privileges that enable individuals to exercise the duties that
require separation are granted to separate individuals.
AC.L2-3.1.5[a] - ANSWERSprivileged accounts are identified.
AC.L2-3.1.5[b] - ANSWERSaccess to privileged accounts is authorized in accordance with the
principle of least privilege.
AC.L2-3.1.5[c] - ANSWERSsecurity functions are identified.
AC.L2-3.1.5[d] - ANSWERSaccess to security functions is authorized in accordance with the
principle of least privilege.
, AC.L2-3.1.6[a] - ANSWERSnonsecurity functions are identified.
AC.L2-3.1.6[b] - ANSWERSusers are required to use non-privileged accounts or roles when
accessing nonsecurity functions.
AC.L2-3.1.7[a] - ANSWERSprivileged functions are defined.
AC.L2-3.1.7[b] - ANSWERSnon-privileged users are defined.
AC.L2-3.1.7[c] - ANSWERSnon-privileged users are prevented from executing privileged
functions.
AC.L2-3.1.7[d] - ANSWERSthe execution of privileged functions is captured in audit logs.
AC.L2-3.1.8[a] - ANSWERSthe means of limiting unsuccessful logon attempts is defined.
AC.L2-3.1.8[b] - ANSWERSthe defined means of limiting unsuccessful logon attempts is
implemented.
AC.L2-3.1.9[a] - ANSWERSprivacy and security notices required by CUI-specified rules are
identified, consistent, and associated with the specific CUI category.
AC.L2-3.1.9[b] - ANSWERSprivacy and security notices are displayed.
AC.L2-3.1.10[a] - ANSWERSthe period of inactivity after which the system initiates a session lock
is defined.