NIST 800-53 Rev 5

424 controls available

AC-6moderatehigh

Least Privilege

Access Control

Control Statement

Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.

Discussion

Organizations employ least privilege for specific duties and systems. The principle of least privilege is also applied to system processes, ensuring that the processes have access to systems and operate at privilege levels no higher than necessary to accomplish organizational missions or business functions. Organizations consider the creation of additional processes, roles, and accounts as necessary to achieve least privilege. Organizations apply least privilege to the development, implementation, and operation of organizational systems.

Framework
NIST SP 800-53 Rev 5
Family
Access Control
Baselines
moderate, high

Related Frameworks

10 paths across 2 frameworks
NIST 800-1711 mapping
3.1.5
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI9 mappings
CCI-000225
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001558
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002221
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002222
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002223
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002226
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002227
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003685
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003686
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

181 STIGs reach this control through 25 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

7 STIGs

Operating System — Server

40 STIGs
Show 32 more STIGs in this category →
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-178 of 448 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-195 of 216 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-132 of 375 findings match
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-191 of 103 findings match
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-061 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-161 of 283 findings match

Operating System — Mainframe

15 STIGs
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-0913 of 230 findings match
IBM z/OS TSS Security Technical Implementation Guide
92025-06-2413 of 231 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-096 of 222 findings match
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-095 of 225 findings match
CA IDMS Security Technical Implementation Guide
V2R12024-09-134 of 74 findings match
Show 7 more STIGs in this category →
Mainframe Product Security Requirements Guide
V3R42025-09-103 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-053 of 193 findings match

Operating System — Mobile

29 STIGs
Show 21 more STIGs in this category →

Network Device

21 STIGs
Network Device Management Security Requirements Guide
V5R32025-02-112 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-102 of 105 findings match
Cisco ASA NDM Security Technical Implementation Guide
V2R42025-12-081 of 47 findings match
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-111 of 53 findings match
Show 13 more STIGs in this category →
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-191 of 119 findings match

Database

24 STIGs
Show 16 more STIGs in this category →
Database Security Requirements Guide
V4R52026-02-262 of 142 findings match
Database Security Requirements Guide
42024-12-042 of 142 findings match

Web / Application Server

24 STIGs
Application Server Security Requirements Guide
V4R42025-09-102 of 137 findings match
Application Server Security Requirements Guide
42025-02-112 of 128 findings match
Show 16 more STIGs in this category →
Web Server Security Requirements Guide
V4R42025-09-101 of 126 findings match
Web Server Security Requirements Guide
42025-02-121 of 124 findings match

Virtualization / Container

10 STIGs
Container Platform Security Requirements Guide
V2R42025-09-103 of 188 findings match
Container Platform Security Requirements Guide
22025-05-153 of 187 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-063 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-103 of 198 findings match
Show 2 more STIGs in this category →

Cloud / Identity Service

1 STIG

Endpoint Security Management

6 STIGs

Productivity Application

2 STIGs

Uncategorized

2 STIGs