Mapped to NIST 800-171 Requirement: 3.14.7
CMMC Assessment Objective: SI.L2-3.14.7[a]
What This Control Means
You must proactively monitor and identify when:
• Unauthorized users attempt to access your systems
• Authorized users misuse their access rights
• Unusual or malicious system activities occur
Detection must focus on preventing, logging, and escalating unauthorized activities quickly.
Why It Matters
If unauthorized use isn’t detected:
• CUI could be stolen, exposed, or corrupted
• Internal or external attackers could persist unnoticed
• Incident response and containment efforts would be severely delayed
• Compliance failures would occur under CMMC and DFARS standards
Unauthorized use is often the earliest indicator of a breach—early detection is critical.
How to Implement It
1. Deploy Monitoring Tools Examples:
• SIEM platforms (e.g., Splunk, LogRhythm, Microsoft Sentinel)
• Endpoint Detection and Response (EDR) solutions
• IDS/IPS at network boundaries
2. Define Unauthorized Use Scenarios
• Failed or abnormal login attempts
• Access to restricted resources
• Privilege escalation activities without approval
• Large, unexpected data transfers
3. Document Detection Mechanisms
• Specify how unauthorized use will be detected:
◦ Alert thresholds
◦ Anomaly detection algorithms
◦ Manual log reviews
4. Assign Responsibility
• Security or IT teams must review logs, investigate suspicious events, and escalate incidents
Evidence the Assessor Will Look For
• SSP entries describing how unauthorized system use is monitored
• Security policies and procedures covering detection requirements
• SIEM or EDR system screenshots showing active monitoring rules
• Logs of detected unauthorized access attempts or policy violations
• Incident reports showing investigation and resolution of suspicious activities
Common Gaps
• Monitoring tools installed but unauthorized use detection not configured
• Unauthorized use detection focused only on external threats—not insider threats
• No policies requiring prompt review of suspicious activities
• No documented escalation paths after detection of unauthorized use
How Cuick Trac Helps
Cuick Trac supports this requirement by:
• Tracking detection of unauthorized system use across CUI environments
• Logging attempted unauthorized access events and linking them to user accounts
• Alerting on suspicious activity in real-time for rapid incident response
• Documenting monitoring mechanisms and detection coverage in your SSP
• Providing audit-ready proof that unauthorized system use is proactively monitored and handled
With Cuick Trac, suspicious activity isn’t just caught—it’s logged, escalated, and resolved.
Final CTA
Early detection is your best defense.
Schedule a Cuick Trac demo to monitor and document unauthorized system use to protect your CUI—and your compliance.