This objective requires your organization to identify and document who is authorized to use your systems, especially systems that process, store, or transmit Controlled Unclassified Information (CUI). This helps ensure that only trusted, approved individuals can access your CUI systems.