1. Home
  2. Frameworks and Standards
  3. NIST SP 800-53
  4. NIST SP 800-53 – AC-2(3) – Account Management | Disable Accounts

NIST SP 800-53 – AC-2(3) – Account Management | Disable Accounts

Control(s)

Disable accounts within [Assignment: organization-defined time period] when the accounts:
(a) Have expired;
(b) Are no longer associated with a user or individual;
(c) Are in violation of organizational policy; or
(d) Have been inactive for [Assignment: organization-defined time period].

Additional Details (Discussion)

Disabling expired, inactive, or otherwise anomalous accounts supports the concepts of least privilege and least functionality which reduce the attack surface of the system.

Related Control(s)

  • None.

Reference(s)

Updated on July 16, 2022
Was this article helpful?

Related Articles