NIST 800-53 Rev 5

424 controls available

AC-2lowmoderatehigh

Account Management

Access Control

Control Statement

Define and document the types of accounts allowed and specifically prohibited for use within the system; Assign account managers; Require {{ insert: param, ac-02_odp.01 }} for group and role membership; Specify: Authorized users of the system; Group and role membership; and Access authorizations (i.e., privileges) and {{ insert: param, ac-02_odp.02 }} for each account; Require approvals by {{ insert: param, ac-02_odp.03 }} for requests to create accounts; Create, enable, modify, disable, and remove accounts in accordance with {{ insert: param, ac-02_odp.04 }}; Monitor the use of accounts; Notify account managers and {{ insert: param, ac-02_odp.05 }} within: {{ insert: param, ac-02_odp.06 }} when accounts are no longer required; {{ insert: param, ac-02_odp.07 }} when users are terminated or transferred; and {{ insert: param, ac-02_odp.08 }} when system usage or need-to-know changes for an individual; Authorize access to the system based on: A valid access authorization; Intended system usage; and {{ insert: param, ac-02_odp.09 }}; Review accounts for compliance with account management requirements {{ insert: param, ac-02_odp.10 }}; Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and Align account management processes with personnel termination and transfer processes.

Discussion

Examples of system account types include individual, shared, group, system, guest, anonymous, emergency, developer, temporary, and service. Identification of authorized system users and the specification of access privileges reflect the requirements in other controls in the security plan. Users requiring administrative privileges on system accounts receive additional scrutiny by organizational personnel responsible for approving such accounts and privileged access, including system owner, mission or business owner, senior agency information security officer, or senior agency official for privacy. Types of accounts that organizations may wish to prohibit due to increased risk include shared, group, emergency, anonymous, temporary, and guest accounts. Where access involves personally identifiable information, security programs collaborate with the senior agency official for privacy to establish the specific conditions for group and role membership; specify authorized users, group and role membership, and access authorizations for each account; and create, adjust, or remove system accounts in accordance with organizational policies. Policies can include such information as account expiration dates or other factors that trigger the disabling of accounts. Organizations may choose to define access privileges or other attributes by account, type of account, or a combination of the two. Examples of other attributes required for authorizing access include restrictions on time of day, day of week, and point of origin. In defining other system account attributes, organizations consider system-related requirements and mission/business requirements. Failure to consider these factors could affect system availability. Temporary and emergency accounts are intended for short-term use. Organizations establish temporary accounts as part of normal account activation procedures when there is a need for short-term accounts without the demand for immediacy in account activation. Organizations establish emergency accounts in response to crisis situations and with the need for rapid account activation. Therefore, emergency account activation may bypass normal account authorization processes. Emergency and temporary accounts are not to be confused with infrequently used accounts, including local logon accounts used for special tasks or when network resources are unavailable (may also be known as accounts of last resort). Such accounts remain available and are not subject to automatic disabling or removal dates. Conditions for disabling or deactivating accounts include when shared/group, emergency, or temporary accounts are no longer required and when individuals are transferred or terminated. Changing shared/group authenticators when members leave the group is intended to ensure that former group members do not retain access to the shared or group account. Some types of system accounts may require specialized training.

Framework
NIST SP 800-53 Rev 5
Family
Access Control
Baselines
low, moderate, high

Related Frameworks

54 paths across 2 frameworks
NIST 800-1712 mappings
3.1.1
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.1.2
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI46 mappings
CCI-000008
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000010
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000011
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000012
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000063
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000065
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000213
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001547
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002110
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002111
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002112
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002113
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002114
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002115
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002116
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002117
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002118
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002119
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002120
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002121
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002122
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002123
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002124
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002125
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002126
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002127
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002128
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002129
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002310
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002311
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002312
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003612
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003613
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003614
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003615
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003616
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003617
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003618
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003619
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003620
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003621
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003622
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003623
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003624
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003625
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003626
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

238 STIGs reach this control through 93 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

7 STIGs

Operating System — Server

46 STIGs
Amazon Linux 2023 Security Technical Implementation Guide
V1R32026-02-2711 of 187 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-1311 of 375 findings match
Show 38 more STIGs in this category →
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-179 of 448 findings match
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-066 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-166 of 283 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-196 of 216 findings match
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-193 of 103 findings match

Operating System — Mainframe

35 STIGs
Mainframe Product Security Requirements Guide
V3R42025-09-1016 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-0516 of 193 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-0912 of 222 findings match
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-0911 of 225 findings match
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-0911 of 230 findings match
IBM z/OS TSS Security Technical Implementation Guide
92025-06-2411 of 231 findings match
Show 27 more STIGs in this category →
CA IDMS Security Technical Implementation Guide
V2R12024-09-131 of 74 findings match

Operating System — Mobile

13 STIGs
Show 5 more STIGs in this category →

Network Device

55 STIGs
AAA Services Security Requirements Guide
V2R22024-12-0419 of 77 findings match
Show 47 more STIGs in this category →
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-116 of 53 findings match
Network Device Management Security Requirements Guide
V5R32025-02-116 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-106 of 105 findings match
Cisco ASA NDM Security Technical Implementation Guide
V2R42025-12-085 of 47 findings match
Cisco ACI NDM Security Technical Implementation Guide
V1R22025-12-112 of 26 findings match
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-192 of 119 findings match
RUCKUS ICX NDM Security Technical Implementation Guide
V1R12025-05-281 of 25 findings match

Database

26 STIGs
Database Security Requirements Guide
V4R52026-02-263 of 142 findings match
Database Security Requirements Guide
42024-12-043 of 142 findings match
Show 18 more STIGs in this category →

Web / Application Server

8 STIGs

Virtualization / Container

23 STIGs
Container Platform Security Requirements Guide
V2R42025-09-1017 of 188 findings match
Container Platform Security Requirements Guide
22025-05-1517 of 187 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-0616 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-1016 of 198 findings match
Show 15 more STIGs in this category →
Kubernetes Security Technical Implementation Guide
V2R62026-02-122 of 92 findings match

Cloud / Identity Service

3 STIGs

Endpoint Security Management

19 STIGs
Central Log Server Security Requirements Guide
V3R42026-02-1210 of 127 findings match
Central Log Server Security Requirements Guide
32024-12-0410 of 125 findings match
HYCU Protege Security Technical Implementation Guide
V1R22026-03-046 of 55 findings match
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-146 of 98 findings match
Show 11 more STIGs in this category →
BlackBerry UEM Security Technical Implementation Guide
V2R12020-12-042 of 16 findings match

Productivity Application

3 STIGs