This objective requires organizations to validate that system configurations enforce access restrictions for publicly accessible systems and content, especially where Controlled Unclassified Information (CUI) or sensitive system functions might be involved.