AC.L2-3.1.17[a]: Identify Every Connection to Systems That Handle CUI

Mapped to NIST 800-171 Requirement: 3.1.17
CMMC Assessment Objective: AC.L2-3.1.17[a]

What This Objective Means
You must maintain a clear understanding of all network and system connections that touch any system containing CUI. This includes:
• Internal connections (e.g., workstations, printers, file servers)
• Remote access points (e.g., VPN, RDP, cloud services)
• Third-party or vendor connections
• Interfaces to non-CUI environments
The objective is to build a complete map of how and where CUI flows through your systems.

Why It Matters
Untracked or undocumented connections may:
• Introduce unmonitored access points
• Allow unauthorized data transfer
• Leave CUI systems vulnerable to lateral movement by attackers
This control helps reduce the attack surface and identify potential exposure points.

How to Implement It
• Create and maintain a network diagram or system inventory showing:
◦ All systems handling CUI
◦ All connections into or out of those systems
◦ Connection types (wired, wireless, remote, virtual)
• Review firewall rules, access control lists, and routing tables
• Include cloud service connections, vendor tunnels, and IoT devices where applicable
• Link the inventory to your System Security Plan (SSP) and data flow documentation

Evidence the Assessor Will Look For
• Up-to-date network diagrams or architectural drawings
• System inventory that highlights CUI-hosting systems and their connected interfaces
• Logs showing regular review or validation of these connections
• Documentation identifying the business or technical owner of each connection

Common Gaps
• No formal inventory of system connections
• Outdated network diagrams that don’t reflect current architecture
• Unknown or shadow IT connections not documented or reviewed

How Cuick Trac Helps
Cuick Trac supports this control by:
• Isolating CUI systems in a secure enclave with known, controlled boundaries
• Documenting all internal and external connections to the enclave environment
• Minimizing the number of direct interfaces, reducing tracking overhead
• Helping generate network diagrams and connection inventories for assessment
With Cuick Trac, your CUI connections are always visible, defined, and controlled.

Final CTA
You can’t defend a system if you don’t know what it’s connected to.
Schedule a Cuick Trac demo and bring full visibility to your CUI environment.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.