FedRAMP High
AC - Access Control

FedRAMP High AC-2: Account Management

Manage accounts; review at least monthly for privileged, every six months for non-privileged (FedRAMP); notify within FedRAMP-defined timeframes on changes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 160 controls across 93 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 9 controls

  • 2.2.2 2.2.2 Vendor default accounts managed
  • 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure
  • 6.5.6 6.5.6 Remove test data and accounts before production
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 7.2.3 7.2.3 Privileges approved by authorized personnel
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.2.6 7.2.6 Query access to stored cardholder data restricted

CIS Controls v8 · 7 controls

  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

HIPAA Security Rule · 6 controls

NIST SP 800-66 Rev 2 · 6 controls

C5 (Germany) · 5 controls

  • C5-IDM-01 Policy for user accounts and access rights
  • C5-IDM-02 Granting and change of user accounts and access rights
  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-IDM-04 Withdraw or adjust access rights as the task area changes
  • C5-IDM-05 Regular review of access rights
  • ASBv3-PA-4 Review and reconcile user access regularly
  • IM-1 Use centralized identity and authentication system
  • PA-1 Separate and limit highly privileged/administrative users
  • PA-3 Manage lifecycle of identities and entitlements

ISO 27002:2022 · 4 controls

  • 5.16 Identity management
  • 5.18 Access rights
  • 8.2 Privileged access rights
  • 8.3 Information access restriction

SOC 2 · 4 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties

UK Cyber Essentials · 4 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • CE-AC.4 Privileged Account Approval and Tracking
  • CE-AC.6 Periodic Review of Privileged Access
  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles

ISO 27001:2022 · 3 controls

  • 5.16 Identity management
  • 5.18 Access rights
  • 8.2 Privileged access rights
  • MYHR-REG-11 Ensuring required information is given to the System Operator
  • MYHR-SEC-2 Access controls and user account management

CMMC 2.0 · 2 controls

MTCS (Singapore) · 2 controls

  • MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles
  • MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-Certification MTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance

SASB Standards · 2 controls

  • SASB-3 Leadership and Governance (LG)
  • SASB-LG-1 Business Ethics
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

Bahrain PDPL · 1 control

DORA · 1 control

  • LOPDP-EC-Enforcement-Sanctions-Articles-66-76-SPDP-Investigation-Administrative-Fines-Tiered-Penalty-Habeas-Data Ecuador LOPDP Enforcement + Sanctions + Articles 66-76 + SPDP + Habeas Data
  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution
  • GLI33-Sports-Integrity-DataProviders-Compliance GLI-33 Sports Event Data Integrity, Provider Certification and Regulatory Reporting

GRI Standards · 1 control

  • CBPR-AccountabilityAgents-CertificationProcess Global CBPR Forum: Accountability Agents (TrustArc, Schellman, BBB, JIPDEC) and Certification Process

IEEE 7000 · 1 control

  • IEEE7000-Scope-VBE-EAD-IEEE7000Family-EUAIAct-NIST-ISO42001-Coord IEEE 7000-2021 - Scope + Value-Based Engineering (VBE) + Ethically Aligned Design + IEEE 7000 Family + Coordination EU AI Act + NIST AI RMF + ISO/IEC 42001

ISMAP (Japan) · 1 control

ISO 27701:2019 · 1 control

  • 6.6.2 User access management

ISSB Standards · 1 control

  • ISSB-IFRS-S1-Sources-SASB-Industry-Disclosures-Connected-Information-Reporting-Boundary ISSB IFRS S1 Sources of Guidance + SASB Standards Industry-Specific Disclosures + Connected Information + Reporting Boundary + Time of Reporting + Comparative Information + 11 SASB Sectors

India DPDP Act · 1 control

  • INCDPA-Enforcement-30DayCure-AttorneyGeneralOnly-NoPrivateRight-CivilPenalties-7500-PerViolation Indiana CDPA Enforcement - Attorney General Exclusive + 30-Day Cure Period + No Private Right of Action + Civil Penalties Up to USD 7500 Per Violation + Investigation + Compliance

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

  • JP-AIG-Accountability-Governance-AI-Inventory-Stakeholder-Engagement-Board-Reporting-Tone-at-Top Japan AI Guidelines Accountability + Governance + AI Inventory + Stakeholder Engagement + Board Reporting + Tone at Top + AI Ethics Committee + DPO + AI Officer + Regulatory Compliance + Multi-Stakeholder

LGPD · 1 control

  • LGPD-BR-Enforcement-Sanctions-ANPD-Article-52-55-Administrative-Sanctions-2-Percent-Turnover-50M-BRL Brazil LGPD Enforcement + Sanctions + Article 52 + 2% Turnover + 50M BRL + ANPD
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Enforcement-PDPC-Investigation-RM1M-Fine-3-Year-Prison-Class-Action-Section-104-2024-Amendment Malaysia PDPA Enforcement + PDPC Investigation + RM1M Fine + 3 Year Prison + Class Action + 2024 Amendment

Mauritius DPA · 1 control

  • MU-DPA-Enforcement-Commissioner-Section-41-43-MUR-200K-5-Year-Prison-ICT-Appeal-Tribunal-Supreme-Court Mauritius DPA Enforcement + Commissioner + Section 41 + Section 43 + MUR 200K + 5 Year Prison + ICT Appeal Tribunal + Supreme Court

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Enforcement-INAI-Articles-63-64-67-320K-Days-Minimum-Wage-3-Year-Prison-TFJA-Recurso-Revision-SCJN Mexico LFPDPPP Enforcement + INAI + Articles 63-64-67 + 320K Days Minimum Wage + 3 Year Prison + TFJA + Recurso de Revision + SCJN
  • MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification
  • MT-CDPA-Processor-Contract-Security-MCA-30-14-2809-30-14-2811-Pseudonymisation-De-Identification Montana CDPA Processor + MCA 30-14-2809 + Security + Pseudonymisation + MCA 30-14-2811 + De-Identification
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-1 On-Demand Self-Service and Broad Network Access Characteristics

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

  • NIST190-04 Regulatory compliance for cloud services
  • AC-2 AC-2 Account Management
  • AC-2 AC-2 Account Management
  • AC-2 AC-2 Account Management
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NZISM-2 Certification and Accreditation (C&A) for Government Systems
  • NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition

OECD AI Principles · 1 control

  • OECDAI-8 AI Incident Reporting, Regulatory Compliance, Public Reporting, and International Cooperation
  • DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Singapore · 1 control

  • PDPASG-7 Retention Limitation, Do Not Call, Compliance, Complaints

PDPA Thailand · 1 control

  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training

POPIA · 1 control

  • POPIASA-8 Information Regulator Cooperation, Complaints, Enforcement
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

Privacy Act 2020 · 1 control

  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • EHDSREG-5 Cross-Border Health Data Flows

Saudi Arabia PDPL · 1 control

  • SA-PDPL-25 Compliance monitoring and auditing

South Korea PIPA · 1 control

  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • TCFDREC-1 Governance - Board Oversight, Management Role

Taiwan PDPA · 1 control

  • TAIWAN-4 DPIA, Privacy by Design
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • UKAI-2 Sector-Specific Regulator Engagement

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP

Vietnam PDPD · 1 control

  • VIETNAMPDP-3 Data Subject Rights

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-4 Privacy Notice and DPIA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AC - Access Control

You are reading one control. How much of FedRAMP High have you already done?

FedRAMP High AC-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP High your existing evidence covers. Hold C5 (Germany) and 119 of 410 FedRAMP High controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 6 were rejected on the C5 (Germany) pair alone.

Query this from an agent

The graph holds this control, the 160 it maps to, and the evidence behind each claim, over MCP and REST.