CMMCpedia Download

Requirements / System and Communications Protection (SC)

SC.L2-3.13.3

Role Separation

Official Source Material

Separate user functionality from system management functionality.

Determine if:

  1. [a] user functionality is identified;
  2. [b] system management functionality is identified; and
  3. [c] user functionality is separated from system management functionality.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

You define what counts as user functionality and what counts as system management.

Objectives [a] and [b] are definitions you write, and the definitions frame the assessment. Defining system management functionality as domain and tenant administration and user functionality as what a standard account can do is a workable framing. A least-privilege paragraph that never says what either term means gives the assessor nothing to test [c] against.

Separate accounts enforce the separation. Separate networks are optional.

The requirement allows physical or logical separation, and logical separation through access control is the ordinary implementation. Administrators hold a standard account for daily work and a privileged account for administration, and standard accounts cannot reach the administrative functions. This is the same account discipline AC.L2-3.1.6 requires, evidenced from the other side.

Prove [c] by showing what a standard user cannot do.

A demonstration that a normal account cannot open the admin center, install software, or reach management interfaces is direct evidence. Pair it with the definitions and the account inventory, and the requirement is covered without new infrastructure.

Jump servers and privileged access management platforms are upgrades, not requirements.

A dedicated administration host confines privileged sessions, and a privileged access management tool adds checkout and recording. Both earn roadmap space in a larger environment. Neither is needed to meet the objectives when account separation is clean.

What falls short

  • A policy stating that least privilege is employed on all accounts, with no definition of user or system management functionality. It leaves [a] and [b] unanswered and gives [c] nothing to demonstrate against.

Edge cases

  • Developers who need local administrator rights can keep them without breaking this requirement. Define privileged functionality at the domain or tenant level, grant local administrator through a documented risk exception, and alert on the actions you prohibited. The separate privileged account for domain work still applies.
  • In a three-person company the same person holds both roles. The separation is between accounts, not people: one everyday account, one administrative account, and the everyday one cannot administer.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.