id: "AC-03(11)" title: "Restrict Access to Specific Information Types" family: "AC" family_name: "Access Control" sort_id: "ac-03.11" priority: "P1" implementation_level: "system" parent: "AC-03" enhancement: True
Statement
Restrict access to data repositories containing {{ insert: param, ac-03.11_odp }}.
Guidance
Restricting access to specific information is intended to provide flexibility regarding access control of specific information types within a system. For example, role-based access could be employed to allow access to only a specific type of personally identifiable information within a database rather than allowing access to the database in its entirety. Other examples include restricting access to cryptographic keys, authentication information, and selected system information.
Assessment Objective
access to data repositories containing {{ insert: param, ac-03.11_odp }} is restricted.
Access control policy
procedures addressing access enforcement
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel with access enforcement responsibilities
organizational personnel with responsibilities for data repositories
system/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing access enforcement functions