CMMCpedia Download

Requirements / System and Information Integrity (SI)

SI.L2-3.14.7

Identify Unauthorized Use

Official Source Material

Identify unauthorized use of organizational systems.

Determine if:

  1. [a] authorized use of the system is defined; and
  2. [b] unauthorized use of the system is identified.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Objective [a] is your acceptable use policy doing double duty.

Define authorized use of the system: who may use it, for what, with which software and services. The acceptable use policy people sign under your awareness program is the definition. Keep it specific enough that unauthorized has a meaning.

Not every prohibition needs a technical detector.

Objective [b] asks that unauthorized use is identified, not that every policy line has a sensor. Technical items get technical detection: alerts on unauthorized software from your inventory tooling, connections refused for unenrolled devices, log review flagging odd hours or odd volume. Non-technical prohibitions, such as photographing a screen, are covered by policy, training, and the duty to report that you place on everyone.

The mechanisms are ones you already run.

Endpoint detections, the log review from AU.L2-3.3.1, application inventory reports, and the network monitoring from SI.L2-3.14.6 all surface use outside the definition. Name them as the identification mechanisms in your system security plan, the document that says how each requirement is met. Objective [b] then points at running machinery instead of intent.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.