Mapped to NIST 800-171 Requirement: 3.13.2
CMMC Assessment Objective: SC.L2-3.13.2[c]
What This Control Means
Every connection that transfers or exposes CUI—whether internal or external—must be:
• Reviewed for security risks
• Approved by an authorized person or body
• Documented as an approved connection
• Re-reviewed periodically as part of your risk or change management processes
This ensures you control the flow of CUI and prevent unauthorized data exposure.
Why It Matters
Unauthorized connections can:
• Create backdoors for threat actors
• Enable CUI to be exfiltrated or intercepted
• Introduce unmanaged or insecure third-party systems
• Violate contractual or regulatory requirements
Authorization provides a formal decision point to evaluate and control access.
How to Implement It
1. Create an Authorization Process
• Define:
◦ What qualifies as a “connection”
◦ Who can approve new connections
◦ What documentation is required for approval
2. Maintain an Authorized Connection Register
• Track:
◦ Description of the connection
◦ Associated systems
◦ Date approved
◦ Approver’s name/role
◦ Next scheduled review
3. Use Change Management to Control New Connections
• Require security review before any new:
◦ API integration
◦ Cloud interconnect
◦ VPN setup
◦ Vendor platform access
4. Review and Audit Periodically
• Re-authorize connections after major system changes
• Include connections in quarterly or annual access reviews
Evidence the Assessor Will Look For
• Records of who approved each CUI-related system connection
• Connection authorization forms or approval logs
• Policies defining the approval process and roles involved
• SSP entries referencing authorized connections
• Evidence of connection reviews during security assessments
Common Gaps
• Connections exist without formal authorization
• No policy or workflow for approving system-to-system interfaces
• Connections approved informally (e.g., via email) with no record
• Legacy connections persist with no current approval trail
How Cuick Trac Helps
Cuick Trac supports this requirement by:
• Providing workflows for connection authorization and tracking
• Maintaining a searchable list of approved system interfaces
• Logging who approved each connection and when
• Linking authorized connections to data flows and access controls
• Flagging connections due for review or lacking full approval
With Cuick Trac, every connection into your CUI environment is known, approved, and documented.
Final CTA
If it touches your systems, it needs your approval.
Schedule a Cuick Trac demo to authorize and track every connection that moves CUI through your network.