Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(4)(ii)(C) NIST SP 800-66 Rev 2
Administrative
NIST SP 800-66 Rev 2 164.308(a)(4)(ii)(C): Access Establishment and Modification (Addressable) Implement policies that document, review, and modify a user's right of access. NIST recommends periodic recertification and just-in-time elevation for privileged tasks.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 56 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-5.1 Establish and Maintain an Inventory of Accounts CIS-5.3 Disable Dormant Accounts CIS-6.1 Establish an Access Granting Process CIS-6.2 Establish an Access Revoking Process CIS-6.7 Centralize Access Control CIS-6.8 Define and Maintain Role-Based Access Control 5.16 Identity management 5.18 Access rights 8.2 Privileged access rights 8.3 Information access restriction CE-AC.1 User Account Approval Process CE-AC.3 Remove or Disable Accounts When No Longer Required CE-AC.6 Periodic Review of Privileged Access CE-SC.1 Remove or Disable Unused Software C5-IDM-02 Granting and change of user accounts and access rights C5-IDM-04 Withdraw or adjust access rights as the task area changes C5-IDM-05 Regular review of access rights AC-2 Account Management AC-6(7) Review of User Privileges PS-5 Personnel Transfer AC-2 Account Management AC-6(7) Review of User Privileges PS-5 Personnel Transfer SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12) SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties ASBv3-PA-4 Review and reconcile user access regularly PA-3 Manage lifecycle of identities and entitlements 5.18 Access rights 8.2 Privileged access rights 8.2.4 8.2.4 User ID lifecycle changes authorized 7.2.4 7.2.4 User accounts and privileges reviewed every six months E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures ASD37-18 Restrict administrative privileges (Essential) MYHR-SEC-2 Access controls and user account management 6.6.2 User access management NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 56 it maps to, and the evidence behind each claim, over MCP and REST.