NIST SP 800-53 – AC-3 – Access Enforcement Control(s) Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. Additional...
NIST SP 800-53 – AC-1 – Policy and Procedures Control(s) a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: 1. [Selection (one or more): Organization-level; Mission/business process-level;...
NIST SP 800-53 – AC-14(1) – Permitted Actions Without Identification or Authentication | Necessary Uses Control(s) [Withdrawn: Incorporated into AC-14.] Additional Details (Discussion) N/A Related Control(s) Reference(s) NIST SP 800-53 Rev-5
NIST SP 800-53 – AC-2 – Account Management Control(s) a. Define and document the types of accounts allowed and specifically prohibited for use within the system; b. Assign...
NIST SP 800-53 – AC-3(2) – Access Enforcement | Dual Authorization Control(s) Enforce dual authorization for [Assignment: organization-defined privileged commands and/or other organization-defined actions]. Additional Details (Discussion) Dual authorization, also known...
NIST SP 800-53 – AC-2(1) – Account Management | Automated System Account Management Control(s) Support the management of system accounts using [Assignment: organization-defined automated mechanisms]. Additional Details (Discussion) Automated system account management includes...
NIST SP 800-53 – AC-3(3) – Access Enforcement | Mandatory Access Control Control(s) Enforce [Assignment: organization-defined mandatory access control policy] over the set of covered subjects and objects specified in the policy,...
NIST SP 800-53 – AC-2(2) – Account Management | Automated Temporary and Emergency Account Management Control(s) Automatically [Selection: remove; disable] temporary and emergency accounts after [Assignment: organization-defined time period for each type of account]. Additional...
NIST SP 800-53 – AC-3(4) – Access Enforcement | Discretionary Access Control Control(s) Enforce [Assignment: organization-defined discretionary access control policy] over the set of covered subjects and objects specified in the policy,...
NIST SP 800-53 – AC-2(3) – Account Management | Disable Accounts Control(s) Disable accounts within [Assignment: organization-defined time period] when the accounts: (a) Have expired; (b) Are no longer associated with...