CMMC Level 1 · Assessment ObjectiveSEC / OBJAC.L1-b.1.iii(b)
Access Control · AC.L1-b.1.iii(b)
The use of external systems is identified
An assessment objective under requirement AC.L1-b.1.iii, External Connections, in the Access Control domain.
Objective Statement
the use of external systems is identified
Source · NIST SP 800-171A
Objective identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- Access Control (AC)
- Objective ID
- AC.L1-b.1.iii(b)
- Parent Requirement
- AC.L1-b.1.iii · Verify and control connections to external systems
Assessment Procedures
The official government assessment method for this objective, from NIST SP 800-171A. An assessor examines artifacts, interviews people, and tests mechanisms to determine the result.
Examine
- Access control policy
- procedures addressing account management
- system security plan
- system design documentation
- system configuration settings and associated documentation
- list of active system accounts and the name of the individual associated with each account
- notifications or records of recently transferred, separated, or terminated employees
- list of conditions for group and role membership
- list of recently disabled system accounts along with the name of the individual associated with each account
- access authorization records
- account management compliance reviews
- system monitoring records
- system audit logs and records
- list of devices and systems authorized to connect to organizational systems
- other relevant documents or records
Interview
- Personnel with account management responsibilities
- system or network administrators
- personnel with information security responsibilities
Test
- Organizational processes for managing system accounts
- mechanisms for implementing account management
Related Objectives
- AC.L1-b.1.iii(a)connections to external systems are identified
- AC.L1-b.1.iii(c)connections to external systems are verified
- AC.L1-b.1.iii(d)the use of external systems is verified
- AC.L1-b.1.iii(e)connections to external systems are controlled/limited
- AC.L1-b.1.iii(f)the use of external systems is controlled/limited
Source Authority
- Primary Authority
- NIST SP 800-171A
- Requirement Authority
- FAR 52.204-21(b)(1)
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog logs the determination for this objective with its evidence and source record, so your Level 1 self-assessment stays traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make.
