PS.L3-3.9.2e Damage Limiting

Ensure that organizational systems are protected if adverse information develops or is obtained about individuals with access to CUI.

Source: NIST SP 800-172 3.9.2e

Discussion: If adverse information develops or is obtained about an individual with access to CUI which calls into question whether the individual should have continued access to systems containing CUI, actions are taken (e.g., preclude or limit further access by the individual, audit actions taken by the individual) to protect the CUI while the adverse information is resolved.

SPRS Score: N/A