Mapped to NIST 800-171 Requirement: 3.13.12
CMMC Assessment Objective: SC.L2-3.13.12[b]
What This Control Means
After identifying your authorized users (SC.L2-3.13.12[a]), this control ensures you have written evidence showing:
• Who has system access
• What systems or data they can access
• Their assigned role and permission level
• When and why access was granted
The documentation must reflect reality and be up-to-date.
Why It Matters
Without documented authorized users:
• You can’t prove access is based on need-to-know
• Dormant, rogue, or unauthorized accounts could persist
• You’ll fail basic access control portions of your CMMC audit
• Internal security reviews and investigations become impossible
Documenting authorized users turns access control from theory into verified practice.
How to Implement It
1. Maintain a User Access List Include for each user:
• Name
• Unique user ID
• Systems/platforms accessed
• Assigned role (standard user, admin, privileged user, etc.)
• Business justification (e.g., project, department)
• Access approval date
2. Link to Access Management Systems
• Sync the user list with Active Directory, Azure AD, Okta, or internal access control systems
• Ensure service accounts and contractors are included and properly labeled
3. Store Documentation Securely
• In your System Security Plan (SSP)
• In dedicated user access inventories
• Inside your governance, risk, and compliance (GRC) platform
4. Include Periodic Review Procedures
• Mark when the user list was last reviewed
• Define a quarterly or semiannual review schedule in your access control policy
Evidence the Assessor Will Look For
• System Security Plan (SSP) sections listing authorized users
• User access inventories aligned with system assets
• Role definitions and permission mappings
• Screenshots of Active Directory or user management dashboards
• Access review reports or audit records
Common Gaps
• User access lists incomplete or missing for CUI-related systems
• No mapping between users, systems, and roles
• Lists updated manually without review cycles or ownership
• No formal documentation proving business justification for access
How Cuick Trac Helps
Cuick Trac supports this requirement by:
• Maintaining live, centralized lists of authorized users for every CUI-connected system
• Mapping users to their roles, permissions, and justification records
• Automating access review reminders and documentation updates
• Providing version-controlled evidence for internal audits and CMMC assessments
• Linking authorized users to risk, system, and compliance records in your SSP
With Cuick Trac, your authorized users aren’t just controlled—they’re documented, traceable, and compliant.
Final CTA
Good security starts with knowing who’s inside.
Schedule a Cuick Trac demo to document your authorized user base and build a solid foundation for CUI protection.