Frameworks / NIST SP 800-53 Rev 5 / NIST800-AC-6 What else in your programme already covers this This control maps to 197 controls across 75 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted 3.4.2 3.4.2 Remote access blocks copying or relocating PAN 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians 5.3.5 5.3.5 Users cannot disable or alter anti-malware 6.5.5 6.5.5 No live PANs in pre-production 7.2.1 7.2.1 Access control model defined 7.2.2 7.2.2 User access assigned by job function and least privilege 7.3.2 7.3.2 Access control system enforces role-based permissions 7.3.3 7.3.3 Access control default deny all 8.2.2 8.2.2 Shared and generic IDs only by exception 8.2.4 8.2.4 User ID lifecycle changes authorized 9.2.3 9.2.3 Physical protection of network hardware and lines 9.2.4 9.2.4 Locking of consoles in sensitive areas 9.4.1 9.4.1 Physical security of all media 9.4.4 9.4.4 Management approval for media leaving facility 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse 7.2.5 7.2.5 Application and system accounts least privilege 7.2.6 7.2.6 Query access to stored cardholder data restricted 7.3.1 7.3.1 Need-to-know access control system covers all components 8.6.1 8.6.1 Interactive use of system accounts controlled 5.15 Access control 5.18 Access rights 8.18 Use of privileged utility programs 8.2 Privileged access rights 8.3 Information access restriction 8.31 Separation of development, test and production environments 8.4 Access to source code 6.6 Access control 6.6.1 Business requirements of access control 6.6.2 User access management 6.6.4 System and application access control 7.3.6 Access, correction and/or erasure 7.4.2 Limit processing 7.4.4 PII minimization objectives CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work CIS-16.10 Apply Secure Design Principles in Application Architectures CIS-3.3 Configure Data Access Control Lists CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts CIS-6.8 Define and Maintain Role-Based Access Control AC-6 Least Privilege AC-6(1) Authorize Access to Security Functions AC-6(10) Prohibit Non-Privileged Users from Executing Privileged Functions AC-6(2) Non-Privileged Access for Nonsecurity Functions AC-6(5) Privileged Accounts RA-5(5) Privileged Access AC-6 Least Privilege AC-6(1) Authorize Access to Security Functions AC-6(10) Prohibit Non-Privileged Users from Executing Privileged Functions AC-6(2) Non-Privileged Access for Nonsecurity Functions AC-6(5) Privileged Accounts RA-5(5) Privileged Access 5.15 Access control 5.18 Access rights 8.18 Use of privileged utility programs 8.2 Privileged access rights 8.3 Information access restriction 8.4 Access to source code ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources ANSSI-HYG-27 Prohibit Internet Access from Administration Workstations and Servers ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need ASBv3-AM-4 Limit access to asset management ASBv3-IM-2 Protect identity and authentication systems ASBv3-PA-7 Follow just enough administration (least privilege) principle PA-1 Separate and limit highly privileged/administrative users PA-2 Avoid standing access for user accounts and permissions C5-IDM-01 Policy for user accounts and access rights C5-IDM-02 Granting and change of user accounts and access rights C5-IDM-05 Regular review of access rights C5-IDM-06 Privileged access rights C5-PSS-08 Roles and Rights Concept SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties SOC2-P5.1 P5.1 Data subject access SOC2-PI1.3 PI1.3 Controls over system processing E8-ADMIN-ML1 Restrict Administrative Privileges (ML1) E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) E8-ADMIN-ML3 Restrict Administrative Privileges (ML3) ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-21 Disable local administrator accounts (Excellent) CE-AC.4 Privileged Account Approval and Tracking CE-AC.5 Separate Admin Accounts for Administrative Activities CE-AC.6 Periodic Review of Privileged Access AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) SSAE18-CC6.2 CC6.2 - New User Registration and Authorization SSAE18-SOC1-06 Transaction Processing Controls SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment AESCSF-IAM-2 Access control BSI-02 Access enforcement and least privilege DSO-3 Data Access Management CAT-IRP-4 Organizational characteristics GDPR-Art.29 Processing under the authority of the controller or processor 62351-8 Role-based access control (RBAC) ISO-19650-2-5.7 Information model delivery ISO27799-01 ePHI access controls and authorization 27011-8.1 User Endpoint Devices ISO27043-14 Privileged access management 27400-6.1 Secure Device Design ISO21434-14 Privileged access management Art.21.2.g Basic cyber hygiene practices and cybersecurity training NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties 3.13.2e Introduce Unpredictability into System Operations NIST190-08 Privileged access in cloud environments AC-6 AC-6 Least Privilege AC-6 AC-6 Least Privilege NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PTESPHASE-2 Intelligence Gathering (OSINT) SHAREASSESS-2 Access Control, Identity, Authentication SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule CISABD-1 Take Ownership of Customer Security Outcomes SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain SIGSTORE-2 Transparency Log (Rekor) and Verification ISMSP-AC-01 Access Control Policy TSAPIPE-2 OT/IT Network Segmentation and Access Control UK-TSA-NET-02 Access Control and Authentication ACE-CR-4 Cargo Release Authorization UGA-10 Sensitive Personal Data Prohibition Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in AC - Access Control You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-AC-6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 197 it maps to, and the evidence behind each claim, over MCP and REST.