NIST SP 800-53 Rev 5
AC - Access Control

NIST SP 800-53 Rev 5 NIST800-AC-2: AC-2 Account Management

a. Define and document the types of accounts allowed and specifically prohibited for use within the system; b. Assign account managers; c. Require [Assignment: organization-defined prerequisites and criteria] for group and role membership; d. Specify: 1. Authorized users of the system; 2. Group and role membership; and 3. Access authorizations (i.e., privileges) and [Assignment: organization-defined attributes (as required)] for each account; e. Require approvals by [Assignment: organization-defined personnel or roles] for requests to create accounts; f. Create, enable, modify, disable, and remove accounts in accordance with [Assignment: organization-defined policy, procedures, prerequisites, and criteria]; g. Monitor the use of accounts; h. Notify account managers and [Assignment: organization-defined personnel or roles] within: 1. [Assignment: organization-defined time period] when accounts are no longer required; 2. [Assignment: organization-defined time period] when users are terminated or transferred; and 3. [Assignment: organization-defined time period] when system usage or need-to-know changes for an individual; i. Authorize access to the system based on: 1. A valid access authorization; 2. Intended system usage; and 3. [Assignment: organization-defined attributes (as required)]; j. Review accounts for compliance with account management requirements [Assignment: organization-defined frequency]; k. Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and l. Align account management processes with personnel termination and transfer processes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 256 controls across 102 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 14 controls

  • 2.2.2 2.2.2 Vendor default accounts managed
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 7.2.3 7.2.3 Privileges approved by authorized personnel
  • 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 8.2.5 8.2.5 Terminated users' access revoked immediately
  • 8.2.6 8.2.6 Inactive accounts removed within 90 days
  • 8.2.7 8.2.7 Third-party remote access accounts controlled
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.3.1.1 9.3.1.1 Personnel access to sensitive areas controlled
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 8.6.1 8.6.1 Interactive use of system accounts controlled

FedRAMP High · 12 controls

  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(3) Disable Accounts
  • AC-2(4) Automated Audit Actions
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(7) Review of User Privileges
  • RA-5(5) Privileged Access

FedRAMP Moderate · 12 controls

  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(3) Disable Accounts
  • AC-2(4) Automated Audit Actions
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(7) Review of User Privileges
  • RA-5(5) Privileged Access

CIS Controls v8 · 9 controls

  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-5.6 Centralize Account Management
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.8 Define and Maintain Role-Based Access Control
  • ASBv3-LT-2 Enable threat detection for identity and access management
  • ASBv3-PA-4 Review and reconcile user access regularly
  • ASBv3-PA-5 Set up emergency access
  • IM-1 Use centralized identity and authentication system
  • PA-1 Separate and limit highly privileged/administrative users
  • PA-2 Avoid standing access for user accounts and permissions
  • PA-3 Manage lifecycle of identities and entitlements

HIPAA Security Rule · 5 controls

NIST SP 800-66 Rev 2 · 5 controls

  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources

C5 (Germany) · 4 controls

  • C5-IDM-02 Granting and change of user accounts and access rights
  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-IDM-04 Withdraw or adjust access rights as the task area changes
  • C5-IDM-05 Regular review of access rights

ISO 27002:2022 · 4 controls

  • 5.15 Access control
  • 5.16 Identity management
  • 5.18 Access rights
  • 8.2 Privileged access rights

ISO 27701:2019 · 4 controls

  • 6.4.2 During employment
  • 6.6 Access control
  • 6.6.1 Business requirements of access control
  • 6.6.2 User access management

NIST SP 800-207 · 4 controls

SOC 2 · 4 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO 27799:2025 · 3 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-08 Information access management
  • ISO27799-17 Facility access controls

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/SAE 21434 · 3 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification

NIST SP 1800-32 · 3 controls

UK Cyber Essentials · 3 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • CE-AC.4 Privileged Account Approval and Tracking
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-21 Disable local administrator accounts (Excellent)
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls

ISO 27001:2022 · 2 controls

  • 5.16 Identity management
  • 5.18 Access rights

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • MYHR-SEC-2 Access controls and user account management
  • AESCSF-IAM-2 Access control

Bahrain PDPL · 1 control

  • ZTMM-ID-AO Identity Pillar: Automation and Orchestration

CMMC 2.0 · 1 control

CMMC 2.0 Level 1 · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 62351-8 Role-based access control (RBAC)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ITIL 4 · 1 control

  • ITIL4-15 Access management for services

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • AC-2 AC-2 Account Management
  • AC-2 AC-2 Account Management
  • AC-2 AC-2 Account Management
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PTES · 1 control

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

  • QATAR-5 Security of Processing
  • SHAREASSESS-2 Access Control, Identity, Authentication
  • SOC-CY-S1 Logical and Physical Access Controls

Saudi Arabia PDPL · 1 control

  • SA-PDPL-15 Access control for personal data
  • SIGSTORE-2 Transparency Log (Rekor) and Verification

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TEXASTDPSA-2 Consumer Rights
  • UKGAMBLE-4 Resilience and Incident Response
  • UK-TSA-NET-02 Access Control and Authentication
  • CPSC-CS.2 Authentication and Access Controls
  • US-ITAR-EAR-DS-03 Access Controls

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AC - Access Control

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-AC-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 256 it maps to, and the evidence behind each claim, over MCP and REST.