1Overview
SI.L2-3.14.7 closes the System and Information Integrity family, and the 110 Level 2 requirements, by requiring that unauthorized use be recognized. It requires that unauthorized use of organizational systems be identified, which depends first on having defined what authorized use is, so that use outside the permitted bounds can be told apart from legitimate activity. It is a three-point requirement that cannot be deferred on a plan of action.
Identifying unauthorized use requires a baseline: unauthorized use can only be recognized against a definition of what authorized use looks like. This control requires that authorized use of the system be defined and that unauthorized use then be identified against that definition. Without the definition, unusual activity has nothing to be measured against; with it, use that falls outside the authorized pattern can be spotted. It draws on the monitoring the rest of the family provides, turning that visibility into the recognition of misuse. The two assessment objectives are defining authorized use and identifying unauthorized use.
Identify unauthorized use of organizational systems.
The requirement is to identify unauthorized use, and the assessment objectives make explicit that this rests on first defining authorized use. Authorized use of the system is defined, establishing the baseline of legitimate activity; then unauthorized use is identified, recognized as activity that departs from that baseline. Defining the authorized pattern is what makes unauthorized use identifiable rather than merely suspected.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.14.7 into two objectives: define authorized use and identify unauthorized use.
Authorized use of the system is defined. The baseline of legitimate activity is established.
Unauthorized use of the system is identified. Use outside the authorized baseline is recognized.
The two objectives are the definition and the identification. The common gap is at objective [a], where authorized use is never defined, so unauthorized use has no baseline to be recognized against. The assessor looks for defined authorized use and identification of use outside it.
3Failure Patterns
The failures are about misuse that cannot be told from legitimate use.
Authorized use undefined
Without a definition of authorized use, unusual activity has nothing to be measured against, and unauthorized use blends in. Defining authorized use establishes the baseline.
No identification of misuse
Defining authorized use but never identifying departures from it leaves misuse unrecognized. Identification against the baseline completes the control.
No monitoring to draw on
Identifying unauthorized use depends on visibility into system activity. Without monitoring to draw on, the identification has nothing to work from.
4Ownership
This is a security-owned control that draws on system monitoring.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Defines authorized use and identifies unauthorized use against it. Owns the evidence. |
| IT and security | Provides the monitoring and activity data used to identify misuse. |
| Program lead | Confirms authorized use is defined and unauthorized use identified, and retains records. |
5Tooling
The control is delivered by a defined use baseline and monitoring that identifies departures.
| Objective | Tooling | What it provides |
|---|---|---|
| [a] | Defined authorized use policy | The baseline of legitimate activity. |
| [b] | Monitoring and anomaly detection | Identification of use outside the baseline. |
The caveat is that both the definition and the identification have to be present, and the identification depends on monitoring to draw from. A defined baseline with no identification, or identification attempted without a baseline, leaves the control unmet. The assessor examines both objectives, so definition and identification have to hold.
6Evidence
The satisfied version of 3.14.7 shows defined authorized use and identified unauthorized use.
| Evidence | What it demonstrates |
|---|---|
| Authorized use definition | Objective [a]. The baseline of legitimate activity. |
| Unauthorized use identification records | Objective [b]. Use outside the baseline recognized. |
The evidence should show authorized use defined and unauthorized use identified against it. The authorized use definition together with the identification records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.
Misuse is visible only against a definition of the normal
Unauthorized use can be recognized only against a defined baseline of authorized use, so this three-point control asks that authorized use be defined and departures from it identified. Establishing that baseline and the means to spot misuse is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.7. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.14.7[a] and 3.14.7[b]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.7 among the three-point derived security requirements. ecfr.gov