Skip to content

Family 3.1 22 requirements The largest family

Access Control.

Who gets in. What they can do. How remote and mobile work.

The big picture

If you nail Access Control, you've handled the biggest family in the standard. If you don't, the assessor will find most of their findings here.

How many of these 22 your cloud platform contributes to varies — see what your cloud handles vs what you own for the per-platform breakdown.

Theme 1

Who and what.

3.1.1 — 3.1.7

Who has access, what they can do, least privilege, separation of duties, and logging admin work.

Theme 2

Session controls.

3.1.8 — 3.1.11

Locking out failed logins, login banners, auto-lock, and session termination.

Theme 3

Remote access.

3.1.12 — 3.1.15

Monitoring remote connections, encrypting them, routing through managed gateways, controlling remote admin.

Theme 4

Wireless & mobile.

3.1.16 — 3.1.19

Authorising wireless, encrypting it, managing mobile devices, encrypting CUI on portable devices.

Theme 5

External & media.

3.1.20 — 3.1.22

Controlling connections to outside systems, USB drives, and keeping CUI off public systems.