DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.3
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.3  Separate User and Management Functionality

Separate user functionality from system management functionality.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

SC.L2-3.13.3 requires that ordinary use and system administration be kept apart. It requires that user functionality be separated from system management functionality, so that the interfaces and privileges people use for everyday work are distinct from those used to administer the system. It is a one-point requirement and may be deferred on a plan of action.

When everyday user functions and system management functions share the same interfaces or accounts, a compromise of ordinary use can reach administrative capability. This control requires that the two be separated: user functionality, the applications and interfaces people use to do their work, kept distinct from system management functionality, the tools and interfaces used to administer the system. Separating them means a foothold in the user environment does not automatically grant management capability. The three assessment objectives are identifying each kind of functionality and separating them.

The requirement · NIST SP 800-171 Rev 2, 3.13.3

Separate user functionality from system management functionality.

The requirement is to separate user functionality from system management functionality, and the assessment objectives add identifying each first. User functionality is identified, system management functionality is identified, and the two are then separated, whether by distinct interfaces, separate systems, or isolated accounts and privileges. The separation ensures that administrative capability is not exposed through the everyday user environment.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.13.3 into three objectives: identify user functionality, identify management functionality, and separate them.

[a]

User functionality is identified. The everyday user functions are known.

MeetsUser functionality is identified.
FailsUser functionality is not distinguished from management.
[b]

System management functionality is identified. The administrative functions are known.

MeetsSystem management functionality is identified.
FailsManagement functionality is not distinguished.
[c]

User functionality is separated from system management functionality. The two are kept apart.

MeetsUser and management functionality are separated by interface, system, or privilege.
FailsUser and management functions share the same interface or account.

The three objectives are identify each and separate them. The common failure is at objective [c], where management functions are reachable from the ordinary user environment. The assessor looks for both functions identified and genuinely separated.

3Failure Patterns

The failures are about administrative capability exposed through everyday use.

Management reachable from user environment

Where administrative interfaces are available from the same environment users work in, a user-side compromise reaches management. Separating the two removes that path.

Shared accounts for both

Accounts used for both everyday work and administration blur the separation. Distinct accounts and privileges keep the functions apart.

Functions not distinguished

Without identifying which functions are user and which are management, the separation cannot be applied. Identification is the basis for separation.

The common root
This control fails when convenience collapses the two roles into one environment. It is easier to administer from the same place work is done, but that easy path is exactly what an attacker uses to escalate from a user foothold to system control. Separating the functions removes the shortcut for both the administrator and the attacker.

4Ownership

This is an IT and system administration-owned control.

RoleResponsibility for this control
IT and system administratorIdentifies and separates user and management functionality. Owns the separation evidence.
System architectsDesign the separation into the environment.
Security or compliance leadConfirms management functions are not reachable from the user environment.
See also: This control complements the privileged-account controls of the access control family and the security engineering of SC.L2-3.13.2.

5Tooling

The control is delivered by separating user and management interfaces, systems, or privileges.

ObjectivesToolingWhat it provides
[a], [b]Functionality identificationDistinguished user and management functions.
[c]Separate interfaces, systems, or privileged accountsSeparation of the two.

The caveat is that the separation has to be real, not nominal. Management functions reachable from the user environment, even through a different menu, are not separated. The assessor examines identification and genuine separation, so all three objectives have to hold.

6Evidence

The satisfied version of 3.13.3 shows user and management functionality kept apart.

EvidenceWhat it demonstrates
Functionality identificationObjectives [a], [b]. User and management functions identified.
Separation configurationObjective [c]. The two kept apart by interface, system, or privilege.

The evidence should show user and management functionality identified and separated. The identification together with the separation configuration is the clearest demonstration of the control.

A user foothold should not reach the controls

When everyday use and administration share an environment, a user-side compromise escalates to system control, so this control asks that user functionality be separated from system management functionality. Building that separation is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.3[a] through 3.13.3[c]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.2 · Security Engineering Principles
Next in System and Communications Protection →
SC.L2-3.13.4 · Prevent Unauthorized Transfer via Shared Resources
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.3 · Edition 2026.1 · Last reviewed July 12, 2026