CMMC -NIST 800-171
Control Compliance Hub
Control Register
Control ID
Description
Level
Status
Responsible
Bitrix Task
Deadline
Implementation
Validation
Findings
Recommendations
Comments
Actions
AC.L1-3.1.1
Limit system access to authorized users, processes acting on behalf of users, and devices (including identification and enforcement)
Level 1
In Progress
Margie Collins
17606
2026-04-29
Task 1 — Unique User Identification (IA.L1-3.5.1)
1. Go to: Entra ID → Users
2. Verify:
• Each user has a unique account
• No shared accounts exist
3. Disable any shared/generic accounts
📸 Evidence:
• User list screenshot
• Disabled accounts (if applicable)
🔹 Task 2 — Enforce Authentication (IA.L1-3.5.2)
1. Go to: Entra ID → Security → Authentication Methods
2. Enable:
• Microsoft Authenticator
• SMS (optional backup)
3. Go to: Conditional Access
4. Confirm MFA policy is enforced (from AC task)
Alternate location:
👉 Conditional Access (Recommended / Modern)
Go to:
👉 https://entra.microsoft.com
Entra ID → Security → Conditional Access → Policies
Look for a policy like:
• Require MFA
• Require MFA and Compliant Device
• Or whatever you named it
📸 Evidence:
• MFA settings
• Policy enforcement
Edit
AC.L1-3.1.2
Limit system access to the types of transactions and functions authorized users are permitted to execute
Level 1
In Progress
Olivia Cruz-Martinez
17608
0000-00-00
Edit
AC.L1-3.1.20
Control and verify use of external systems
Level 1
In Progress
Margie Collins
17644
0000-00-00
Edit
AC.L1-3.1.22
Control posting of information on publicly accessible systems
Level 1
In Progress
Olivia Cruz-Martinez
17648
0000-00-00
Edit
IA.L1-3.5.1
Identify users, processes, and devices
Level 1
In Progress
Olivia Cruz-Martinez
17692
0000-00-00
Edit
IA.L1-3.5.2
Authenticate users, processes, and devices
Level 1
In Progress
Olivia Cruz-Martinez
17694
0000-00-00
Edit
MP.L1-3.8.1
Physically control and securely store media
Level 1
In Progress
Byran Pham
17840
0000-00-00
Edit
MP.L1-3.8.3
Sanitize or destroy media before disposal/reuse
Level 1
In Progress
Margie Collins
17736
0000-00-00
Edit
PE.L1-3.10.1
Limit physical access to authorized individuals
Level 1
In Progress
Byran Pham
17750
0000-00-00
Edit
PE.L1-3.10.3
Escort and monitor visitors
Level 1
In Progress
Margie Collins
17754
0000-00-00
Edit
PE.L1-3.10.4
Maintain physical access logs
Level 1
In Progress
Margie Collins
17756
0000-00-00
Edit
PE.L1-3.10.5
Control physical access devices
Level 1
In Progress
Margie Collins
17758
0000-00-00
Edit
SI.L1-3.14.1
Identify, report, and correct system flaws
Level 1
In Progress
Byran Pham
17780
0000-00-00
Edit
SI.L1-3.14.1
Identify, report, and correct system flaws
Level 1
In Progress
Margie Collins
17812
0000-00-00
Edit
SI.L1-3.14.2
Provide malicious code protection
Level 1
In Progress
Olivia Cruz-Martinez
17814
0000-00-00
Edit
SI.L1-3.14.5
Perform malware scans
Level 1
In Progress
Margie Collins
17820
0000-00-00
Edit
Open Tasks
Control ID
Level
Status
Responsible
Bitrix Task No.
Deadline
Comments
AC.L1-3.1.1
Level 1
In Progress
Margie Collins
17606
2026-04-29
AC.L1-3.1.2
Level 1
In Progress
Olivia Cruz-Martinez
17608
0000-00-00
AC.L1-3.1.20
Level 1
In Progress
Margie Collins
17644
0000-00-00
AC.L1-3.1.22
Level 1
In Progress
Olivia Cruz-Martinez
17648
0000-00-00
IA.L1-3.5.1
Level 1
In Progress
Olivia Cruz-Martinez
17692
0000-00-00
IA.L1-3.5.2
Level 1
In Progress
Olivia Cruz-Martinez
17694
0000-00-00
MP.L1-3.8.1
Level 1
In Progress
Byran Pham
17840
0000-00-00
MP.L1-3.8.3
Level 1
In Progress
Margie Collins
17736
0000-00-00
PE.L1-3.10.1
Level 1
In Progress
Byran Pham
17750
0000-00-00
PE.L1-3.10.3
Level 1
In Progress
Margie Collins
17754
0000-00-00
PE.L1-3.10.4
Level 1
In Progress
Margie Collins
17756
0000-00-00
PE.L1-3.10.5
Level 1
In Progress
Margie Collins
17758
0000-00-00
SI.L1-3.14.1
Level 1
In Progress
Byran Pham
17780
0000-00-00
SI.L1-3.14.1
Level 1
In Progress
Margie Collins
17812
0000-00-00
SI.L1-3.14.2
Level 1
In Progress
Olivia Cruz-Martinez
17814
0000-00-00
SI.L1-3.14.5
Level 1
In Progress
Margie Collins
17820
0000-00-00
Findings & Recommendations
Control ID
Level
Findings
Recommendations
Responsible
Deadline
No findings or recommendations found.