Skip to main content
ControlFrame
Public source instrument

Authority and catalog facts only. No customer evidence is read, no assessment method is activated, and no control conclusion is recorded here.

Catalog context ≠ assessment result
Framework library

Catalog Observatory

NIST SP 800-53

Rev. 5, Release 5.2.0

Trace one authority signal through its exact source, normalized catalog, retained method context, and required human decision. The signal stops wherever the record stops.

Authority record
primary
Current edition
Rev. 5
Release
5.2.0
Published
Aug 27, 2025
Authority checked
Aug 26, 2026
Catalog reader
Release connected
NIST Computer Security Resource CenterSource-bound

Source-to-decision path

The provenance beam

Ends at named human acceptance
  1. Authority

    primary source · checked 2026-08-26Rev. 5, Release 5.2.0 is the registry's current edition.
  2. Source

    Source artifact boundExact release artifact · SHA-256 01f37cf90ea9…6e9bc062. Full digest remains visible below.
  3. Catalog

    1,196 catalog units indexedNormalized catalog · SHA-256 bfae171ee609…aaacbcc7.
  4. Reference method

    3,715 assessment-objective nodes retained · inactive2,931 method parts and 2,931 object parts are preserved for reference; no runnable test set is activated by this catalog reader.
  5. Human acceptance

    Required · no conclusion recordedThe reference method may prepare a review record. A named reviewer retains conclusion authority.

A later station can exist as configuration without inheriting the authority of an earlier one. Only a connected path carries provenance; only a named reviewer can accept a conclusion.

Observation coordinates

Select the record to inspect

Catalog units
1,196
controls + enhancements
Active
1,014
operative records
Withdrawn
182
retained lineage
Statements
1,016
source statements
Guidance
1,014
guidance entries
ODPs
1,600
organization-defined parameters

Catalog index

1,196 matching catalog units

Showing 50 of 1196
  1. AC-1ACPolicy and Proceduresactiveguidance9 ODPs1 assessment records
  2. AC-2ACAccount Managementactiveguidance10 ODPs1 assessment records
  3. AC-2(1)ACAutomated System Account Managementactiveguidance1 ODPs1 assessment records
  4. AC-2(2)ACAutomated Temporary and Emergency Account Managementactiveguidance2 ODPs1 assessment records
  5. AC-2(3)ACDisable Accountsactiveguidance2 ODPs1 assessment records
  6. AC-2(4)ACAutomated Audit Actionsactiveguidance1 assessment records
  7. AC-2(5)ACInactivity Logoutactiveguidance1 ODPs1 assessment records
  8. AC-2(6)ACDynamic Privilege Managementactiveguidance1 ODPs1 assessment records
  9. AC-2(7)ACPrivileged User Accountsactiveguidance1 ODPs1 assessment records
  10. AC-2(8)ACDynamic Account Managementactiveguidance1 ODPs1 assessment records
  11. AC-2(9)ACRestrictions on Use of Shared and Group Accountsactiveguidance1 ODPs1 assessment records
  12. AC-2(10)ACShared and Group Account Credential Changewithdrawn
  13. AC-2(11)ACUsage Conditionsactiveguidance2 ODPs1 assessment records
  14. AC-2(12)ACAccount Monitoring for Atypical Usageactiveguidance2 ODPs1 assessment records
  15. AC-2(13)ACDisable Accounts for High-risk Individualsactiveguidance2 ODPs1 assessment records
  16. AC-3ACAccess Enforcementactiveguidance1 assessment records
  17. AC-3(1)ACRestricted Access to Privileged Functionswithdrawn
  18. AC-3(2)ACDual Authorizationactiveguidance1 ODPs1 assessment records
  19. AC-3(3)ACMandatory Access Controlactiveguidance5 ODPs1 assessment records
  20. AC-3(4)ACDiscretionary Access Controlactiveguidance3 ODPs1 assessment records
  21. AC-3(5)ACSecurity-relevant Informationactiveguidance1 ODPs1 assessment records
  22. AC-3(6)ACProtection of User and System Informationwithdrawn
  23. AC-3(7)ACRole-based Access Controlactiveguidance3 ODPs1 assessment records
  24. AC-3(8)ACRevocation of Access Authorizationsactiveguidance1 ODPs1 assessment records
  25. AC-3(9)ACControlled Releaseactiveguidance3 ODPs1 assessment records
  26. AC-3(10)ACAudited Override of Access Control Mechanismsactiveguidance2 ODPs1 assessment records
  27. AC-3(11)ACRestrict Access to Specific Information Typesactiveguidance1 ODPs1 assessment records
  28. AC-3(12)ACAssert and Enforce Application Accessactiveguidance1 ODPs1 assessment records
  29. AC-3(13)ACAttribute-based Access Controlactiveguidance1 ODPs1 assessment records
  30. AC-3(14)ACIndividual Accessactiveguidance2 ODPs1 assessment records
  31. AC-3(15)ACDiscretionary and Mandatory Access Controlactiveguidance6 ODPs1 assessment records
  32. AC-4ACInformation Flow Enforcementactiveguidance1 ODPs1 assessment records
  33. AC-4(1)ACObject Security and Privacy Attributesactiveguidance11 ODPs1 assessment records
  34. AC-4(2)ACProcessing Domainsactiveguidance1 ODPs1 assessment records
  35. AC-4(3)ACDynamic Information Flow Controlactiveguidance1 ODPs1 assessment records
  36. AC-4(4)ACFlow Control of Encrypted Informationactiveguidance3 ODPs1 assessment records
  37. AC-4(5)ACEmbedded Data Typesactiveguidance1 ODPs1 assessment records
  38. AC-4(6)ACMetadataactiveguidance1 ODPs1 assessment records
  39. AC-4(7)ACOne-way Flow Mechanismsactiveguidance1 assessment records
  40. AC-4(8)ACSecurity and Privacy Policy Filtersactiveguidance10 ODPs1 assessment records
  41. AC-4(9)ACHuman Reviewsactiveguidance2 ODPs1 assessment records
  42. AC-4(10)ACEnable and Disable Security or Privacy Policy Filtersactiveguidance6 ODPs1 assessment records
  43. AC-4(11)ACConfiguration of Security or Privacy Policy Filtersactiveguidance3 ODPs1 assessment records
  44. AC-4(12)ACData Type Identifiersactiveguidance1 ODPs1 assessment records
  45. AC-4(13)ACDecomposition into Policy-relevant Subcomponentsactiveguidance1 ODPs1 assessment records
  46. AC-4(14)ACSecurity or Privacy Policy Filter Constraintsactiveguidance3 ODPs1 assessment records
  47. AC-4(15)ACDetection of Unsanctioned Informationactiveguidance4 ODPs1 assessment records
  48. AC-4(16)ACInformation Transfers on Interconnected Systemswithdrawn
  49. AC-4(17)ACDomain Authenticationactiveguidance1 ODPs1 assessment records
  50. AC-4(18)ACSecurity Attribute Bindingwithdrawn

The server returns at most 50 records per view. Refine the source query or family to inspect the remainder; the full catalog is never shipped to a browser bundle.

Field notebook · source record

AC-1

Access Control
active

Policy and Procedures

The statement below is source material, not a generated control summary.

01

Source statement

Develop, document, and disseminate to {{ insert: param, ac-1_prm_1 }}: {{ insert: param, ac-01_odp.03 }} access control policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the implementation of the access control policy and the associated access controls; Designate an {{ insert: param, ac-01_odp.04 }} to manage the development, documentation, and dissemination of the access control policy and procedures; and Review and update the current access control: Policy {{ insert: param, ac-01_odp.05 }} and following {{ insert: param, ac-01_odp.06 }} ; and Procedures {{ insert: param, ac-01_odp.07 }} and following {{ insert: param, ac-01_odp.08 }}.

02

Guidance

Access control policy and procedures address the controls in the AC family that are implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that security and privacy programs collaborate on the development of access control policy and procedures. Security and privacy program policies and procedures at the organization level are preferable, in general, and may obviate the need for mission- or system-specific policies and procedures. The policy can be included as part of the general security and privacy policy or be represented by multiple policies reflecting the complex nature of organizations. Procedures can be established for security and privacy programs, for mission or business processes, and for systems, if needed. Procedures describe how the policies or controls are implemented and can be directed at the individual or role that is the object of the procedure. Procedures can be documented in system security and privacy plans or in one or more separate documents. Events that may precipitate an update to access control policy and procedures include assessment or audit findings, security incidents or breaches, or changes in laws, executive orders, directives, regulations, policies, standards, and guidelines. Simply restating controls does not constitute an organizational policy or procedure.

03

Organization-defined parameters

Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.

ac-1_prm_1

organization-defined personnel or roles

ac-01_odp.01

personnel or roles

Source guidance
  • personnel or roles to whom the access control policy is to be disseminated is/are defined;
ac-01_odp.02

personnel or roles

Source guidance
  • personnel or roles to whom the access control procedures are to be disseminated is/are defined;
ac-01_odp.03

Organization-defined parameter

Allowed selection · one-or-more
  • organization-level
  • mission/business process-level
  • system-level
ac-01_odp.04

official

Source guidance
  • an official to manage the access control policy and procedures is defined;
ac-01_odp.05

frequency

Source guidance
  • the frequency at which the current access control policy is reviewed and updated is defined;
ac-01_odp.06

events

Source guidance
  • events that would require the current access control policy to be reviewed and updated are defined;
ac-01_odp.07

frequency

Source guidance
  • the frequency at which the current access control procedures are reviewed and updated is defined;
ac-01_odp.08

events

Source guidance
  • events that would require procedures to be reviewed and updated are defined;
04

Assessment reference context

Retained, not activated.1 source assessment records and 17 objective nodes are available as reference context. This surface runs none of them.

ac-1_objAC-0117 objective nodes
  1. an access control policy is developed and documented;
  2. the access control policy is disseminated to {{ insert: param, ac-01_odp.01 }};
  3. access control procedures to facilitate the implementation of the access control policy and associated controls are developed and documented;
  4. the access control procedures are disseminated to {{ insert: param, ac-01_odp.02 }};
  5. the {{ insert: param, ac-01_odp.03 }} access control policy addresses purpose;
  6. the {{ insert: param, ac-01_odp.03 }} access control policy addresses scope;
  7. the {{ insert: param, ac-01_odp.03 }} access control policy addresses roles;
  8. the {{ insert: param, ac-01_odp.03 }} access control policy addresses responsibilities;
  9. the {{ insert: param, ac-01_odp.03 }} access control policy addresses management commitment;
  10. the {{ insert: param, ac-01_odp.03 }} access control policy addresses coordination among organizational entities;
  11. the {{ insert: param, ac-01_odp.03 }} access control policy addresses compliance;
  12. the {{ insert: param, ac-01_odp.03 }} access control policy is consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines;
  13. the {{ insert: param, ac-01_odp.04 }} is designated to manage the development, documentation, and dissemination of the access control policy and procedures;
  14. the current access control policy is reviewed and updated {{ insert: param, ac-01_odp.05 }};
  15. the current access control policy is reviewed and updated following {{ insert: param, ac-01_odp.06 }};
  16. the current access control procedures are reviewed and updated {{ insert: param, ac-01_odp.07 }};
  17. the current access control procedures are reviewed and updated following {{ insert: param, ac-01_odp.08 }}.
05

Reference method and authority

  1. InputExact release, source digest, control ID, and cited source fields
  2. Agent taskPrepare a bounded evidence request or test-plan draft
  3. Fail closedAbstain when source, scope, or assessment identity is missing
  4. Human acceptanceA named reviewer decides whether evidence supports the conclusion

Release identity

Source and normalized digests

Source artifact
data/frameworks/catalogs/nist-sp-800-53-rev5/5.2.0/source/NIST_SP-800-53_rev5_catalog.json.gz
Source SHA-256
01f37cf90ea99d92242c936cbfbdebcc338eef1f71454e2acac36cc56e9bc062
Catalog SHA-256
bfae171ee60951925f14cf5fc01c7749ce9d94e5ce65ffa68966374caaacbcc7
Assessment activation
Retained only · inactive
Assessment reference corpus
1,014 objective sets · 3,715 objective nodes · 2,787 with prose
Method and object context
2,931 method parts · 2,931 object parts
Inspect NIST OSCAL Content v1.5.0 · OSCAL 1.2.2 (opens in a new tab)
Catalog Observatory: framework explorer | ControlFrame