Frameworks / NIST SP 800-53 Rev 5 / NIST800-AC-7 NIST SP 800-53 Rev 5
AC - Access Control
NIST SP 800-53 Rev 5 NIST800-AC-7: AC-7 Unsuccessful Logon Attempts a. Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]; and b. Automatically [Selection (one or more): lock the account or node for an [Assignment: organization-defined time period]; lock the account or node until released by an administrator; delay next logon prompt per [Assignment: organization-defined delay algorithm]; notify system administrator; take other [Assignment: organization-defined action]] when the maximum number of unsuccessful attempts is exceeded.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 156 controls across 87 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures ISO27799-01 ePHI access controls and authorization ISO27799-08 Information access management ISO27799-17 Facility access controls ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures ISO27043-11 Access control policy and enforcement ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO21434-12 User access management and provisioning ISO21434-14 Privileged access management ISO21434-15 Access review and recertification SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls DSO-2 Data Security DSO-3 Data Access Management CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes SUPCHAIN-1 Build Integrity - Source, Build, Provenance SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule ISMSP-AC-01 Access Control Policy ISMSP-AC-04 Network Access Control CE-SC.5 Password-Based Authentication Quality CE-SC.9 Device Unlocking Credentials and Brute-Force Protection APPI-A26 Report of Leakage to the Commission and Notification to the Person ASBv3-LT-2 Enable threat detection for identity and access management C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices CA-ITSG33-SC-01 Security Control Catalogue FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) AC-7 Unsuccessful Logon Attempts AC-7 Unsuccessful Logon Attempts UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) 62351-8 Role-based access control (RBAC) 8.5 Secure authentication 8.5 Secure authentication ISO28001-PS-01 Facility Security ISO20000-15 Access management for services ITIL4-15 Access management for services NISTPF-5 Protect-P Access Control (PR.AC-P) AC-7 AC-7 Unsuccessful Logon Attempts AC-7 AC-7 Unsuccessful Logon Attempts AC-7 AC-7 Unsuccessful Logon Attempts NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PTESPHASE-2 Intelligence Gathering (OSINT) NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information QATAR-5 Security of Processing SHAREASSESS-2 Access Control, Identity, Authentication SOC-CY-S1 Logical and Physical Access Controls SA-PDPL-15 Access control for personal data SIGSTORE-2 Transparency Log (Rekor) and Verification PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TSAPIPE-2 OT/IT Network Segmentation and Access Control TAIWAN-3 Data Subject Rights TEXASTDPSA-2 Consumer Rights UKGAMBLE-4 Resilience and Incident Response SEMD-PS-2 Site Security Measures UK-TSA-NET-02 Access Control and Authentication CPSC-CS.2 Authentication and Access Controls US-ITAR-EAR-DS-03 Access Controls URUGUAY-3 Sensitive Data, Health Data, Children VIETNAMPDP-2 Consent and Notice VIRGINIAVCDPA-3 Sensitive Data Consent and Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in AC - Access Control You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-AC-7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 156 it maps to, and the evidence behind each claim, over MCP and REST.