This assessment objective ensures that only authorized individuals can access organizational systems that store or process Controlled Unclassified Information (CUI). Organizations must demonstrate that they have defined and enforced access controls to prevent unauthorized access.
👉 This supports the core requirement 3.1.1 in NIST SP 800-171 Rev. 2.