Dr. Ron Ross on the 14 NIST 800-171 Control Families

Access control is one of the largest and most scrutinized families in CMMC. The foundation is deceptively simple: do you know where your CUI flows? Organizations that can’t answer that question struggle to enforce access controls across identity systems, applications, and cloud services. When it’s done right, CUI is mapped from the start, systems are in sync, and privilege is assigned based on mission need — no more, no less.

Identification and authentication is the engine beneath Access Control — and it’s where assessors find the most preventable failures. The premise is simple: can you prove every user, device, and process is who it claims to be? Organizations that can’t tend to share the same blind spots — default credentials never changed, MFA gaps on legacy apps, shared accounts with no individual accountability. When it’s done right, every identity is unique, every device is inventoried, and MFA has no exceptions.