Requirements / Access Control (AC)
AC.L2-3.1.22
Control Public Information
Official Source Material
Control information posted or processed on publicly accessible information systems.
Determine if:
- [a] individuals authorized to post or process information on publicly accessible systems are identified;
- [b] procedures to ensure FCI is not posted or processed on publicly accessible systems are identified;
- [c] a review process is in place prior to posting of any content to publicly accessible systems;
- [d] content on publicly accessible systems is reviewed to ensure that it does not include FCI; and
- [e] mechanisms are in place to remove and address improper posting of FCI.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
This requirement can never sit on a POA&M.
A POA&M is the plan of action that buys time for unfinished requirements, and 32 CFR 170.21(a)(2)(iii) excludes AC.L2-3.1.22 from Level 2 plans of action. A missing review process blocks even a Conditional CMMC Status. The good news is that this is among the cheapest requirements in the family to meet.
An hour of procedure writing covers four of the five objectives.
Name who may post to the website and official social media [a]. Write the procedure that keeps CUI and FCI out of public systems [b]. CUI is the controlled unclassified information your contract requires you to protect. FCI is the non-public information the government provides, or you generate for it, under your contract. Require review before anything is posted [c], and define how improper postings get removed and reported [e]. One page in your media or acceptable use policy is a complete answer, and write it to cover CUI as well as the FCI the objectives name.
Objective [d] needs a recurring review of what is already public.
Pre-posting review alone does not answer it. Review the live site on a defined schedule, and record who reviewed and when. A dated sign-off in a spreadsheet is adequate. An annual review is a defensible floor for a static site. A change-detection alert that triggers review of modified pages is a sound supplement, not a substitute for the pre-posting step.
Company channels are in scope. Personal ones are not.
The company website and official social media accounts get the authorization and review process. Employees' personal accounts are not subject to pre-publication review, and no objective requires monitoring them. An employee posting FCI from a personal account is an incident to handle under [e] and a training matter under AT.L2-3.2.1, not a gap in this requirement.
What falls short
- Policies and procedures with no recorded review of the live site. Objective [d] wants evidence the public content was actually checked, and the absence of records reads as absence of review.
- Post-publication monitoring alone. Objective [c] requires review before posting, so change alerts without a pre-posting step leave [c] unmet.
Edge cases
- In a very small company the same person may end up posting and reviewing. Assessors differ on whether that passes, so separate the two roles whenever a second person exists, and where one truly does not, document the compensating check.
- A website hosted by a third party is still yours for this requirement. The control is procedural, not technical, so wherever your organization can publish content, the authorization and review process applies.