id: "AC-03(11)" title: "Restrict Access to Specific Information Types" family: "AC" family_name: "Access Control" sort_id: "ac-03.11" priority: "P1" implementation_level: "system" parent: "AC-03" enhancement: True


Statement

Restrict access to data repositories containing {{ insert: param, ac-03.11_odp }}.

Guidance

Restricting access to specific information is intended to provide flexibility regarding access control of specific information types within a system. For example, role-based access could be employed to allow access to only a specific type of personally identifiable information within a database rather than allowing access to the database in its entirety. Other examples include restricting access to cryptographic keys, authentication information, and selected system information.

Assessment Objective

access to data repositories containing {{ insert: param, ac-03.11_odp }} is restricted.

Access control policy

procedures addressing access enforcement

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

Organizational personnel with access enforcement responsibilities

organizational personnel with responsibilities for data repositories

system/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing access enforcement functions