This assessment objective focuses on verifying that your organization uses account management procedures to ensure that only authorized users have access to systems handling Controlled Unclassified Information (CUI). It builds on AC.L2-3.1.1[a] by emphasizing how access is managed—through well-defined, consistent account management practices.