CMMC 1.0 Practice SI.2.217 Requirement:
Identify unauthorized use of organizational systems.
CMMC 1.0 SI.2.217 Requirement Explanation:
Your company's systems should only be used to support its business functions. By defining unauthorized uses of your system and using tools to identify unauthorized use your can better enforce you security policies.
Example CMMC 1.0 SI.2.217 Implementation:
Write out an acceptable use policy. This should specify unauthorized activity such as using your company system for illegal activity. Use the system logs you already collect, your intrusion detection system, anti-virus software, and other tools such as web content filters to identify unauthorized activity.
CMMC 1.0 SI.2.217 Scenario(s):
- Scenario 1:
The anti-virus software deployed to your companies workstations have a web content filtering capability. It filters out various unauthorized websites such as gambling and pornographic sites. Your company's acceptable use policy (signed by each employee) prevents users from using your system to view pornography. One day while reviewing system logs you determine that a user has been regularly viewing pornography. You report the policy violation and the employee is sanctioned.
- Scenario 2:
Upon reviewing network usage logs you identify a workstation on your network that is downloading large mp3 files everyday. Upon further investigation you determine that an employee has been downloading pirated music. You escalate this and the employee is sanctioned.
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you
NIST SP 800-171 & CMMC Compliance
Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC requirements.
Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
FAR 52.204-21 Compliance
Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
ISO 27001 Compliance
Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.