CMMCpedia Download

Requirements / Access Control (AC)

AC.L2-3.1.2

Transaction & Function Control

Official Source Material

Limit system access to the types of transactions and functions that authorized users are permitted to execute.

Determine if:

  1. [a] the types of transactions and functions that authorized users are permitted to execute are defined; and
  2. [b] system access is limited to the defined types of transactions and functions for authorized users.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Objective [a] is a document you write, not a setting.

List the user types in your system, such as standard user, administrator, and finance, and the transactions and functions each may execute. Create, read, update, and delete per system or application is the level of granularity the assessment guide uses. A one-page matrix satisfies [a].

Objective [b] is the enforcement of that matrix.

Show the roles and groups that implement it: Microsoft 365 role assignments, file share permissions, application roles, or an application control tool. Present the configuration next to the matrix so the assessor can see that what is defined is what is enforced.

You do not need a directory service to meet this.

A four-person shop can use local Windows standard versus administrator accounts and application allowlisting, which blocks unapproved programs. Confine CUI, the controlled unclassified information your contract requires you to protect, to specific application accounts. Define the split and enforce it with what you have. An answer scaled to your size is enough.

Personal use is yours to define, not yours to ban.

Nothing in the requirement forbids web mail or music streaming on a NIST SP 800-171 system. What it requires is that you define the limits and keep personal applications and accounts away from CUI and official duties. A wide personal-use allowance creates work elsewhere, in CM.L2-3.4.7 for least functionality and AC.L2-3.1.20 for external connections. The more personal use you allow, the more you have to control elsewhere.

AC.L2-3.1.1 covers who gets access. This requirement covers what they can do once they have it.

Keep the two answers distinct in your system security plan. Account authorization and inventories live under AC.L2-3.1.1. This requirement is where you show that a proposal writer cannot reach developer tools and a developer cannot reach the HR database.

What falls short

  • Role assignments in an admin portal with no written definition of what each role is permitted to execute. Enforcement without a definition leaves [a] unmet.
  • A corporate-owned, personally enabled model where users install anything they like. Without a denylist, monitoring, and a clear line between personal and official use, access is not limited to defined transactions and functions under [b].

Edge cases

  • A corporate-owned, personally enabled device policy is defensible when written deliberately: name the approved software and connections for official duties, keep personal accounts and apps away from official data, and record management's acceptance of the residual risk. It will draw questions across several requirements, so decide up front whether the convenience is worth the extra evidence you will have to produce.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.