1Overview
SC.L2-3.13.3 requires that ordinary use and system administration be kept apart. It requires that user functionality be separated from system management functionality, so that the interfaces and privileges people use for everyday work are distinct from those used to administer the system. It is a one-point requirement and may be deferred on a plan of action.
When everyday user functions and system management functions share the same interfaces or accounts, a compromise of ordinary use can reach administrative capability. This control requires that the two be separated: user functionality, the applications and interfaces people use to do their work, kept distinct from system management functionality, the tools and interfaces used to administer the system. Separating them means a foothold in the user environment does not automatically grant management capability. The three assessment objectives are identifying each kind of functionality and separating them.
Separate user functionality from system management functionality.
The requirement is to separate user functionality from system management functionality, and the assessment objectives add identifying each first. User functionality is identified, system management functionality is identified, and the two are then separated, whether by distinct interfaces, separate systems, or isolated accounts and privileges. The separation ensures that administrative capability is not exposed through the everyday user environment.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.13.3 into three objectives: identify user functionality, identify management functionality, and separate them.
User functionality is identified. The everyday user functions are known.
System management functionality is identified. The administrative functions are known.
User functionality is separated from system management functionality. The two are kept apart.
The three objectives are identify each and separate them. The common failure is at objective [c], where management functions are reachable from the ordinary user environment. The assessor looks for both functions identified and genuinely separated.
3Failure Patterns
The failures are about administrative capability exposed through everyday use.
Management reachable from user environment
Where administrative interfaces are available from the same environment users work in, a user-side compromise reaches management. Separating the two removes that path.
Shared accounts for both
Accounts used for both everyday work and administration blur the separation. Distinct accounts and privileges keep the functions apart.
Functions not distinguished
Without identifying which functions are user and which are management, the separation cannot be applied. Identification is the basis for separation.
4Ownership
This is an IT and system administration-owned control.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Identifies and separates user and management functionality. Owns the separation evidence. |
| System architects | Design the separation into the environment. |
| Security or compliance lead | Confirms management functions are not reachable from the user environment. |
5Tooling
The control is delivered by separating user and management interfaces, systems, or privileges.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [b] | Functionality identification | Distinguished user and management functions. |
| [c] | Separate interfaces, systems, or privileged accounts | Separation of the two. |
The caveat is that the separation has to be real, not nominal. Management functions reachable from the user environment, even through a different menu, are not separated. The assessor examines identification and genuine separation, so all three objectives have to hold.
6Evidence
The satisfied version of 3.13.3 shows user and management functionality kept apart.
| Evidence | What it demonstrates |
|---|---|
| Functionality identification | Objectives [a], [b]. User and management functions identified. |
| Separation configuration | Objective [c]. The two kept apart by interface, system, or privilege. |
The evidence should show user and management functionality identified and separated. The identification together with the separation configuration is the clearest demonstration of the control.
A user foothold should not reach the controls
When everyday use and administration share an environment, a user-side compromise escalates to system control, so this control asks that user functionality be separated from system management functionality. Building that separation is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.3. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.3[a] through 3.13.3[c]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov