NIST Special Publication 800-171 Revision 2

Date Published: January 28th, 2021

Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3

Author(s): Ron Ross (NIST), Victoria Pillitteri (NIST), Kelley Dempsey (NIST), Mark Riddle (NARA), Gary Guissanie (IDA)

Note: A Class Deviation is in effect as of May 2, 2024 (DEVIATION 2024O0013). The deviation clause requires contractors, who are subject to 252.204-7012, to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. Click Here

3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

Control Family: Access Control

Control Type: Derived

SPRS Value: 1

CMMC Level(s): AC.L2-3.1.4

Top Ten Failed Requirement: No

DIBCAC HIGH Failure Rate (OTS):

50th of 110

Referenced in:

DFARS 252.204-7012

Derived From: NIST SP 800-53r4

  • AC-5

CSF v1.1:

  • PR.AC-4

  • PR.DS-5

NIST 800-171 Control 3.1.4 MITRE ATT&CK Sunburst

NIST SP 800-171r2 Control 3.1.4 → MITRE ATT&CK 14.1

Mapping note: MITRE ATT&CK 14.1 techniques are derived through the NIST SP 800-53 Rev. 4 controls mapped to each NIST SP 800-171 Rev. 2 requirement.

Summary

  • Total mappings: 162
  • Families: 1
  • Outer ring: Technique ID + name

Family counts

  • Separation of Duties: 162 techniques

Usage notes

  • Click a family or technique to zoom in.
  • Click the center to zoom back out.
  • Hover to view technique details.

Discussion:

Separation of duties addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion. Separation of duties includes dividing mission functions and system support functions among different individuals or roles; conducting system support functions with different individuals (e.g., configuration management, quality assurance and testing, system management, programming, and network security); and ensuring that security personnel administering access control functions do not also administer audit functions. Because separation of duty violations can span systems and application domains, organizations consider the entirety of organizational systems and system components when developing policy on separation of duties.

Determining Statements (NIST SP 800-171Ar2)

Upon assessment, assessors must determine if-

3.1.4[a] the duties of individuals requiring separation are defined.
3.1.4[b] responsibilities for duties that require separation are assigned to separate
individuals.
3.1.4[c] access privileges that enable individuals to exercise the duties that require
separation are granted to separate individuals.

Assessors are instructed to-

Examine: [SELECT FROM: Access control policy; procedures addressing divisions of responsibility and separation of duties; system security plan; system configuration settings and associated documentation; list of divisions of responsibility and separation of duties; system access authorizations; system audit logs and records; other relevant documents or records].

Interview: [SELECT FROM: Personnel with responsibilities for defining divisions of responsibility and separation of duties; personnel with information security responsibilities; system or network administrators]. Test: [SELECT FROM: Mechanisms implementing separation of duties policy].

FURTHER DISCUSSION

No one person should be in charge of an entire critical task from beginning to end. Documenting and dividing elements of important duties and tasks between employees reduces intentional or unintentional execution of malicious activities.

Example 1

You are responsible for the management of several key systems within your organization including some that process CUI. You assign the task of reviewing the system logs to two different people. This way, no one person is solely responsible for the execution of this critical security function [c].

Example 2

You are a system administrator. Human Resources notifies you of a new hire, and you create an account with general privileges, but you are not allowed to grant access to systems that contain CUI [a,b]. The program manager contacts the team in your organization that has system administration authority over the CUI systems and informs them which CUI the new hire will need to access. Subsequently, a second system administrator grants access privileges to the new hire [c].

Potential Assessment Considerations

  • Does system documentation identify the system functions or processes that require separation of duties (e.g., function combinations that represent a conflict of interest or an over-allocation of security privilege for one individual) [a]?

ISO/IEC 27001:2013

A.6.1.2 Segregation of duties

NIST SP 800-171r2 Control 3.1.4 → MITRE ATT&CK

NIST SP 800-171r2 Control 3.1.4 → MITRE ATT&CK 14.1

Total Mappings

162
technique references

Families

1
Separation of Duties

Control

3.1.4
AC.L2-3.1.4

Separation of Duties 162 techniques

  • T1003OS Credential Dumping
  • T1003.001LSASS Memory
  • T1003.002Security Account Manager
  • T1003.003NTDS
  • T1003.004LSA Secrets
  • T1003.005Cached Domain Credentials
  • T1003.006DCSync
  • T1003.007Proc Filesystem
  • T1003.008/etc/passwd and /etc/shadow
  • T1021Remote Services
  • T1021.001Remote Desktop Protocol
  • T1021.002SMB/Windows Admin Shares
  • T1021.003Distributed Component Object Model
  • T1021.004SSH
  • T1021.006Windows Remote Management
  • T1047Windows Management Instrumentation
  • T1053Scheduled Task/Job
  • T1053.002At (Windows)
  • T1053.003Cron
  • T1053.005Scheduled Task
  • T1053.006Systemd Timers
  • T1053.007Container Orchestration Job
  • T1055Process Injection
  • T1055.008Ptrace System Calls
  • T1056.003Web Portal Capture
  • T1059Command and Scripting Interpreter
  • T1059.001PowerShell
  • T1059.008Network Device CLI
  • T1070Indicator Removal on Host
  • T1070.001Clear Windows Event Logs
  • T1070.002Clear Linux or Mac System Logs
  • T1070.003Clear Command History
  • T1070.007Clear Network Connection History and Configurations
  • T1070.008Clear Mailbox Data
  • T1070.009Clear Persistence
  • T1072Software Deployment Tools
  • T1078Valid Accounts
  • T1078.001Default Accounts
  • T1078.002Domain Accounts
  • T1078.003Local Accounts
  • T1078.004Cloud Accounts
  • T1087.004Cloud Account
  • T1098Account Manipulation
  • T1098.001Additional Cloud Credentials
  • T1098.002Exchange Email Delegate Permissions
  • T1098.003Add Office 365 Global Administrator Role
  • T1098.004SSH Authorized Keys
  • T1098.005Device Registration
  • T1110Brute Force
  • T1110.001Password Guessing
  • T1110.002Password Cracking
  • T1110.003Password Spraying
  • T1110.004Credential Stuffing
  • T1134Access Token Manipulation
  • T1134.001Token Impersonation/Theft
  • T1134.002Create Process with Token
  • T1134.003Make and Impersonate Token
  • T1134.005SID-History Injection
  • T1136Create Account
  • T1136.001Local Account
  • T1136.002Domain Account
  • T1136.003Cloud Account
  • T1185Browser Session Hijacking
  • T1190Exploit Public-Facing Application
  • T1197BITS Jobs
  • T1210Exploitation of Remote Services
  • T1213Data from Information Repositories
  • T1213.001Confluence
  • T1213.002Sharepoint
  • T1213.003Code Repositories
  • T1218Signed Binary Proxy Execution
  • T1218.007Msiexec
  • T1222File and Directory Permissions Modification
  • T1222.001Windows File and Directory Permissions Modification
  • T1222.002Linux and Mac File and Directory Permissions Modification
  • T1484Domain Policy Modification
  • T1489Service Stop
  • T1495Firmware Corruption
  • T1505Server Software Component
  • T1505.002Transport Agent
  • T1505.003Web Shell
  • T1505.005Terminal Services DLL
  • T1525Implant Internal Image
  • T1528Steal Application Access Token
  • T1530Data from Cloud Storage Object
  • T1537Transfer Data to Cloud Account
  • T1538Cloud Service Dashboard
  • T1542Pre-OS Boot
  • T1542.001System Firmware
  • T1542.003Bootkit
  • T1542.005TFTP Boot
  • T1543Create or Modify System Process
  • T1543.001Launch Agent
  • T1543.002Systemd Service
  • T1543.003Windows Service
  • T1543.004Launch Daemon
  • T1546.003Windows Management Instrumentation Event Subscription
  • T1547.004Winlogon Helper DLL
  • T1547.006Kernel Modules and Extensions
  • T1547.009Shortcut Modification
  • T1547.012Print Processors
  • T1547.013XDG Autostart Entries
  • T1548Abuse Elevation Control Mechanism
  • T1548.002Bypass User Account Control
  • T1548.003Sudo and Sudo Caching
  • T1550Use Alternate Authentication Material
  • T1550.002Pass the Hash
  • T1550.003Pass the Ticket
  • T1552Unsecured Credentials
  • T1552.001Credentials In Files
  • T1552.002Credentials in Registry
  • T1552.006Group Policy Preferences
  • T1552.007Container API
  • T1553Subvert Trust Controls
  • T1553.006Code Signing Policy Modification
  • T1556Modify Authentication Process
  • T1556.001Domain Controller Authentication
  • T1556.003Pluggable Authentication Modules
  • T1556.004Network Device Authentication
  • T1556.005Reversible Encryption
  • T1558Steal or Forge Kerberos Tickets
  • T1558.001Golden Ticket
  • T1558.002Silver Ticket
  • T1558.003Kerberoasting
  • T1559Inter-Process Communication
  • T1559.001Component Object Model
  • T1562Impair Defenses
  • T1562.001Disable or Modify Tools
  • T1562.002Disable Windows Event Logging
  • T1562.004Disable or Modify System Firewall
  • T1562.006Indicator Blocking
  • T1562.007Disable or Modify Cloud Firewall
  • T1562.008Disable Cloud Logs
  • T1562.009Safe Mode Boot
  • T1563Remote Service Session Hijacking
  • T1563.001SSH Hijacking
  • T1563.002RDP Hijacking
  • T1569System Services
  • T1569.001Launchctl
  • T1569.002Service Execution
  • T1574Hijack Execution Flow
  • T1574.004Dylib Hijacking
  • T1574.005Executable Installer File Permissions Weakness
  • T1574.007Path Interception by PATH Environment Variable
  • T1574.008Path Interception by Search Order Hijacking
  • T1574.009Path Interception by Unquoted Path
  • T1574.010Services File Permissions Weakness
  • T1574.012COR_PROFILER
  • T1578Modify Cloud Compute Infrastructure
  • T1578.001Create Snapshot
  • T1578.002Create Cloud Instance
  • T1578.003Delete Cloud Instance
  • T1580Cloud Infrastructure Discovery
  • T1599Network Boundary Bridging
  • T1599.001Network Address Translation Traversal
  • T1601Modify System Image
  • T1601.001Patch System Image
  • T1601.002Downgrade System Image
  • T1606Forge Web Credentials
  • T1609Container Administration Command
  • T1611Escape to Host
  • T1619Cloud Storage Object Discovery

Frameworks & Controls