CMMC 2.0
System and Communications Protection

CMMC 2.0 SC.L2-3.13.3: Role Separation

Separate user functionality from system management functionality so ordinary users are not presented with administrative interfaces.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 29 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 6 controls

  • 2.2.3 2.2.3 Primary functions with different security levels managed
  • 7.3.2 7.3.2 Access control system enforces role-based permissions
  • 6.5.4 6.5.4 Separate roles between production and pre-production
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 8.6.1 8.6.1 Interactive use of system accounts controlled
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ANSSI-HYG-27 Prohibit Internet Access from Administration Workstations and Servers
  • ANSSI-HYG-28 Use a Dedicated and Partitioned Network for Administration
  • ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy
  • ASBv3-PA-6 Use privileged access workstations

ISO 27002:2022 · 2 controls

  • 5.3 Segregation of duties
  • 8.27 Secure system architecture and engineering principles

ISO 27701:2019 · 2 controls

  • 6.3.1 Internal organization
  • 6.9.1 Operational procedures and responsibilities
  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)

C5 (Germany) · 1 control

CIS Controls v8 · 1 control

  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work

FedRAMP High · 1 control

  • SC-2 Separation of System and User Functionality

FedRAMP Moderate · 1 control

  • SC-2 Separation of System and User Functionality

ISO 27001:2022 · 1 control

  • 5.3 Segregation of duties

ISO/IEC 42001:2023 · 1 control

  • 5.3 Roles, responsibilities and authorities
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • 03.01.06 Least Privilege - Privileged Accounts

NIST SP 800-172 · 1 control

  • 3.13.2e Introduce Unpredictability into System Operations
  • NIST800-SC-2 SC-2 Separation of System and User Functionality

SOC 2 · 1 control

  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in System and Communications Protection

You are reading one control. How much of CMMC 2.0 have you already done?

CMMC 2.0 SC.L2-3.13.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 29 it maps to, and the evidence behind each claim, over MCP and REST.