CMMC Practice Requirement:

Identify unauthorized use of organizational systems.

CMMC Requirement Explanation:

Your company's systems should only be used to support its business functions. By defining unauthorized uses of your system and using tools to identify unauthorized use your can better enforce you security policies.

Example CMMC Implementation:

Write out an acceptable use policy. This should specify unauthorized activity such as using your company system for illegal activity. Use the system logs you already collect, your intrusion detection system, anti-virus software, and other tools such as web content filters to identify unauthorized activity.

Scenario(s):

- Scenario 1:

The anti-virus software deployed to your companies workstations have a web content filtering capability. It filters out various unauthorized websites such as gambling and pornographic sites. Your company's acceptable use policy (signed by each employee) prevents users from using your system to view pornography. One day while reviewing system logs you determine that a user has been regularly viewing pornography. You report the policy violation and the employee is sanctioned.

- Scenario 2:

Upon reviewing network usage logs you identify a workstation on your network that is downloading large mp3 files everyday. Upon further investigation you determine that an employee has been downloading pirated music. You escalate this and the employee is sanctioned.
 

Discover Our NIST SP 800-171 Solutions:

 /assets/images/compliance_accelerator_white.png

Compliance Accelerator

For contractors seeking compliance
 /assets/images/quantum_assessor_white.png

Quantum Assessor

For IT service providers
 /assets/images/supply_chain_logo_white.png

Supply Chain Verifier

For contractors seeking to verify partner compliance