FedRAMP High
AC - Access Control

FedRAMP High AC-2: Account Management

Manage accounts; review at least monthly for privileged, every six months for non-privileged (FedRAMP); notify within FedRAMP-defined timeframes on changes.

What else in your programme already covers this

This control maps to 162 controls across 95 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 9 controls

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,
  • 2.3.1 Wireless vendor defaults changed before installation
  • 6.5.6 Test data and accounts removed before production
  • 7.2.2 Access is assigned to users, including privileged users, based on: • Job classification and function. • Least privileges necessary to perform job responsibilities
  • 7.2.3 Required privileges are approved by authorized personnel
  • 8.2.4 Addition, deletion, and modification of user IDs, authentication factors, and other identifier objects are managed as follows: • Authorized with the appropriate approval. • Implemented with only the privileges specified on the documented approval
  • 7.2.4 All user accounts and related access privileges, including third-party/vendor accounts, are reviewed as follows: • At least once every six months. • To ensure user accounts and access remain appropriate based on job function.
  • 7.2.5 All application and system accounts and related access privileges are assigned and managed as follows: • Based on the least privileges necessary for the operability of the system or application. • Access is limited
  • 7.2.6 All user access to query repositories of stored cardholder data is restricted as follows: • Via applications or other programmatic methods, with access and allowed actions based on user roles and least privileges. •

CIS Controls v8 · 7 controls

  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

HIPAA Security Rule · 6 controls

NIST SP 800-66 Rev 2 · 6 controls

C5 (Germany) · 5 controls

  • C5-IDM-01 Policy for user accounts and access rights
  • C5-IDM-02 Granting and change of user accounts and access rights
  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-IDM-04 Withdraw or adjust access rights as the task area changes
  • C5-IDM-05 Regular review of access rights
  • ASBv3-PA-4 Review and reconcile user access regularly
  • IM-1 Use centralized identity and authentication system
  • PA-1 Separate and limit highly privileged/administrative users
  • PA-3 Manage lifecycle of identities and entitlements

ISO 27002:2022 · 4 controls

  • 5.16 Identity management
  • 5.18 Access rights
  • 8.2 Privileged access rights
  • 8.3 Information access restriction

SOC 2 · 4 controls

  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
  • SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
  • SOC2-CC6.2 Prior to granting access, registration and authorization processes are established
  • SOC2-CC6.3 Role-based access and least privilege are enforced

UK Cyber Essentials · 4 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • CE-AC.4 Privileged Account Approval and Tracking
  • CE-AC.6 Periodic Review of Privileged Access
  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles

ISO 27001:2022 · 3 controls

  • 5.16 Identity management
  • 5.18 Access rights
  • 8.2 Privileged access rights
  • MYHR-REG-11 Ensuring required information is given to the System Operator
  • MYHR-SEC-2 Access controls and user account management

CMMC 2.0 · 2 controls

MTCS (Singapore) · 2 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance

SASB Standards · 2 controls

  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

Bahrain PDPL · 1 control

DORA · 1 control

  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution

GRI Standards · 1 control

IEEE 7000 · 1 control

ISMAP (Japan) · 1 control

ISO 14001 · 1 control

  • ISO14001-03 Legal and regulatory compliance obligations

ISO 22000 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27701:2019 · 1 control

  • 6.6.2 User access management

ISO 45001 · 1 control

ISSB Standards · 1 control

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-1 On-Demand Self-Service and Broad Network Access Characteristics

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

  • NIST190-04 Regulatory compliance for cloud services
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NZISM-2 Certification and Accreditation (C&A) for Government Systems
  • NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition

OECD AI Principles · 1 control

  • OECDAI-8 AI Incident Reporting, Regulatory Compliance, Public Reporting, and International Cooperation
  • DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Singapore · 1 control

  • PDPASG-7 Retention Limitation, Do Not Call, Compliance, Complaints

PDPA Thailand · 1 control

  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training

POPIA · 1 control

  • POPIASA-8 Information Regulator Cooperation, Complaints, Enforcement
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

Privacy Act 2020 · 1 control

  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training

Saudi Arabia PDPL · 1 control

South Korea PIPA · 1 control

  • TCFDREC-1 Governance - Board Oversight, Management Role

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

  • UKAI-2 Sector-Specific Regulator Engagement

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AC - Access Control

You are reading one control. How much of FedRAMP High have you already done?

FedRAMP High AC-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP High your existing evidence covers. Hold C5 (Germany) and 119 of 410 FedRAMP High controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 6 were rejected on the C5 (Germany) pair alone.

Query this from an agent

The graph holds this control, the 162 it maps to, and the evidence behind each claim, over MCP and REST.