Frameworks / FedRAMP High / AC-2 What else in your programme already covers this This control maps to 160 controls across 93 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
2.2.2 2.2.2 Vendor default accounts managed 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure 6.5.6 6.5.6 Remove test data and accounts before production 7.2.2 7.2.2 User access assigned by job function and least privilege 7.2.3 7.2.3 Privileges approved by authorized personnel 8.2.4 8.2.4 User ID lifecycle changes authorized 7.2.4 7.2.4 User accounts and privileges reviewed every six months 7.2.5 7.2.5 Application and system accounts least privilege 7.2.6 7.2.6 Query access to stored cardholder data restricted CIS-5.1 Establish and Maintain an Inventory of Accounts CIS-5.3 Disable Dormant Accounts CIS-5.5 Establish and Maintain an Inventory of Service Accounts CIS-6.1 Establish an Access Granting Process CIS-6.2 Establish an Access Revoking Process CIS-6.7 Centralize Access Control CIS-6.8 Define and Maintain Role-Based Access Control C5-IDM-01 Policy for user accounts and access rights C5-IDM-02 Granting and change of user accounts and access rights C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins C5-IDM-04 Withdraw or adjust access rights as the task area changes C5-IDM-05 Regular review of access rights ASBv3-PA-4 Review and reconcile user access regularly IM-1 Use centralized identity and authentication system PA-1 Separate and limit highly privileged/administrative users PA-3 Manage lifecycle of identities and entitlements 5.16 Identity management 5.18 Access rights 8.2 Privileged access rights 8.3 Information access restriction SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties CE-AC.1 User Account Approval Process CE-AC.3 Remove or Disable Accounts When No Longer Required CE-AC.4 Privileged Account Approval and Tracking CE-AC.6 Periodic Review of Privileged Access ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles 5.16 Identity management 5.18 Access rights 8.2 Privileged access rights MYHR-REG-11 Ensuring required information is given to the System Operator MYHR-SEC-2 Access controls and user account management MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-Certification MTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NDPA-1 Applicability, Scope, and Carve-Outs NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance SASB-3 Leadership and Governance (LG) SASB-LG-1 Business Ethics E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment LOPDP-EC-Enforcement-Sanctions-Articles-66-76-SPDP-Investigation-Administrative-Fines-Tiered-Penalty-Habeas-Data Ecuador LOPDP Enforcement + Sanctions + Articles 66-76 + SPDP + Habeas Data UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution GLI33-Sports-Integrity-DataProviders-Compliance GLI-33 Sports Event Data Integrity, Provider Certification and Regulatory Reporting CBPR-AccountabilityAgents-CertificationProcess Global CBPR Forum: Accountability Agents (TrustArc, Schellman, BBB, JIPDEC) and Certification Process IEEE7000-Scope-VBE-EAD-IEEE7000Family-EUAIAct-NIST-ISO42001-Coord IEEE 7000-2021 - Scope + Value-Based Engineering (VBE) + Ethically Aligned Design + IEEE 7000 Family + Coordination EU AI Act + NIST AI RMF + ISO/IEC 42001 6.6.2 User access management ISSB-IFRS-S1-Sources-SASB-Industry-Disclosures-Connected-Information-Reporting-Boundary ISSB IFRS S1 Sources of Guidance + SASB Standards Industry-Specific Disclosures + Connected Information + Reporting Boundary + Time of Reporting + Comparative Information + 11 SASB Sectors INCDPA-Enforcement-30DayCure-AttorneyGeneralOnly-NoPrivateRight-CivilPenalties-7500-PerViolation Indiana CDPA Enforcement - Attorney General Exclusive + 30-Day Cure Period + No Private Right of Action + Civil Penalties Up to USD 7500 Per Violation + Investigation + Compliance JP-AIG-Accountability-Governance-AI-Inventory-Stakeholder-Engagement-Board-Reporting-Tone-at-Top Japan AI Guidelines Accountability + Governance + AI Inventory + Stakeholder Engagement + Board Reporting + Tone at Top + AI Ethics Committee + DPO + AI Officer + Regulatory Compliance + Multi-Stakeholder LGPD-BR-Enforcement-Sanctions-ANPD-Article-52-55-Administrative-Sanctions-2-Percent-Turnover-50M-BRL Brazil LGPD Enforcement + Sanctions + Article 52 + 2% Turnover + 50M BRL + ANPD DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness MY-PDPA-Enforcement-PDPC-Investigation-RM1M-Fine-3-Year-Prison-Class-Action-Section-104-2024-Amendment Malaysia PDPA Enforcement + PDPC Investigation + RM1M Fine + 3 Year Prison + Class Action + 2024 Amendment MU-DPA-Enforcement-Commissioner-Section-41-43-MUR-200K-5-Year-Prison-ICT-Appeal-Tribunal-Supreme-Court Mauritius DPA Enforcement + Commissioner + Section 41 + Section 43 + MUR 200K + 5 Year Prison + ICT Appeal Tribunal + Supreme Court MX-LFPDPPP-Enforcement-INAI-Articles-63-64-67-320K-Days-Minimum-Wage-3-Year-Prison-TFJA-Recurso-Revision-SCJN Mexico LFPDPPP Enforcement + INAI + Articles 63-64-67 + 320K Days Minimum Wage + 3 Year Prison + TFJA + Recurso de Revision + SCJN MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification MT-CDPA-Processor-Contract-Security-MCA-30-14-2809-30-14-2811-Pseudonymisation-De-Identification Montana CDPA Processor + MCA 30-14-2809 + Security + Pseudonymisation + MCA 30-14-2811 + De-Identification NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-1 On-Demand Self-Service and Broad Network Access Characteristics NIST190-04 Regulatory compliance for cloud services AC-2 AC-2 Account Management AC-2 AC-2 Account Management AC-2 AC-2 Account Management NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs NZISM-2 Certification and Accreditation (C&A) for Government Systems NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition OECDAI-8 AI Incident Reporting, Regulatory Compliance, Public Reporting, and International Cooperation DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring PDPASG-7 Retention Limitation, Do Not Call, Compliance, Complaints PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training POPIASA-8 Information Regulator Cooperation, Complaints, Enforcement NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training QATAR-7 DPO, Records, Retention, Marketing, Training EHDSREG-5 Cross-Border Health Data Flows SA-PDPL-25 Compliance monitoring and auditing PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2 TCFDREC-1 Governance - Board Oversight, Management Role TAIWAN-4 DPIA, Privacy by Design TEXASTDPSA-3 Sensitive Data, Children, Sale Notice TURKEYKVKK-3 Special Categories and Sensitive Data UKAI-2 Sector-Specific Regulator Engagement HE-3 FSA compliance requirements URUGUAY-5 Database Registration with AGESIC URCDP VIETNAMPDP-3 Data Subject Rights VIRGINIAVCDPA-4 Privacy Notice and DPIA Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in AC - Access Control You are reading one control. How much of FedRAMP High have you already done? FedRAMP High AC-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP High your existing evidence covers. Hold C5 (Germany) and 119 of 410 FedRAMP High controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 6 were rejected on the C5 (Germany) pair alone.
Query this from an agent The graph holds this control, the 160 it maps to, and the evidence behind each claim, over MCP and REST.