Field notebook · source record
AC-2
Access ControlAccount Management
The statement below is source material, not a generated control summary.
Source statement
Define and document the types of accounts allowed and specifically prohibited for use within the system; Assign account managers; Require {{ insert: param, ac-02_odp.01 }} for group and role membership; Specify: Authorized users of the system; Group and role membership; and Access authorizations (i.e., privileges) and {{ insert: param, ac-02_odp.02 }} for each account; Require approvals by {{ insert: param, ac-02_odp.03 }} for requests to create accounts; Create, enable, modify, disable, and remove accounts in accordance with {{ insert: param, ac-02_odp.04 }}; Monitor the use of accounts; Notify account managers and {{ insert: param, ac-02_odp.05 }} within: {{ insert: param, ac-02_odp.06 }} when accounts are no longer required; {{ insert: param, ac-02_odp.07 }} when users are terminated or transferred; and {{ insert: param, ac-02_odp.08 }} when system usage or need-to-know changes for an individual; Authorize access to the system based on: A valid access authorization; Intended system usage; and {{ insert: param, ac-02_odp.09 }}; Review accounts for compliance with account management requirements {{ insert: param, ac-02_odp.10 }}; Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and Align account management processes with personnel termination and transfer processes.
Guidance
Examples of system account types include individual, shared, group, system, guest, anonymous, emergency, developer, temporary, and service. Identification of authorized system users and the specification of access privileges reflect the requirements in other controls in the security plan. Users requiring administrative privileges on system accounts receive additional scrutiny by organizational personnel responsible for approving such accounts and privileged access, including system owner, mission or business owner, senior agency information security officer, or senior agency official for privacy. Types of accounts that organizations may wish to prohibit due to increased risk include shared, group, emergency, anonymous, temporary, and guest accounts. Where access involves personally identifiable information, security programs collaborate with the senior agency official for privacy to establish the specific conditions for group and role membership; specify authorized users, group and role membership, and access authorizations for each account; and create, adjust, or remove system accounts in accordance with organizational policies. Policies can include such information as account expiration dates or other factors that trigger the disabling of accounts. Organizations may choose to define access privileges or other attributes by account, type of account, or a combination of the two. Examples of other attributes required for authorizing access include restrictions on time of day, day of week, and point of origin. In defining other system account attributes, organizations consider system-related requirements and mission/business requirements. Failure to consider these factors could affect system availability. Temporary and emergency accounts are intended for short-term use. Organizations establish temporary accounts as part of normal account activation procedures when there is a need for short-term accounts without the demand for immediacy in account activation. Organizations establish emergency accounts in response to crisis situations and with the need for rapid account activation. Therefore, emergency account activation may bypass normal account authorization processes. Emergency and temporary accounts are not to be confused with infrequently used accounts, including local logon accounts used for special tasks or when network resources are unavailable (may also be known as accounts of last resort). Such accounts remain available and are not subject to automatic disabling or removal dates. Conditions for disabling or deactivating accounts include when shared/group, emergency, or temporary accounts are no longer required and when individuals are transferred or terminated. Changing shared/group authenticators when members leave the group is intended to ensure that former group members do not retain access to the shared or group account. Some types of system accounts may require specialized training.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-02_odp.01
prerequisites and criteria
Source guidance- prerequisites and criteria for group and role membership are defined;
- ac-02_odp.02
attributes (as required)
Source guidance- attributes (as required) for each account are defined;
- ac-02_odp.03
personnel or roles
Source guidance- personnel or roles required to approve requests to create accounts is/are defined;
- ac-02_odp.04
policy, procedures, prerequisites, and criteria
Source guidance- policy, procedures, prerequisites, and criteria for account creation, enabling, modification, disabling, and removal are defined;
- ac-02_odp.05
personnel or roles
Source guidance- personnel or roles to be notified is/are defined;
- ac-02_odp.06
time period
Source guidance- time period within which to notify account managers when accounts are no longer required is defined;
- ac-02_odp.07
time period
Source guidance- time period within which to notify account managers when users are terminated or transferred is defined;
- ac-02_odp.08
time period
Source guidance- time period within which to notify account managers when system usage or the need to know changes for an individual is defined;
- ac-02_odp.09
attributes (as required)
Source guidance- attributes needed to authorize system access (as required) are defined;
- ac-02_odp.10
frequency
Source guidance- the frequency of account review is defined;
Assessment reference context
Retained, not activated.1 source assessment records and 26 objective nodes are available as reference context. This surface runs none of them.
ac-2_objAC-0226 objective nodes
- account types allowed for use within the system are defined and documented;
- account types specifically prohibited for use within the system are defined and documented;
- account managers are assigned;
- {{ insert: param, ac-02_odp.01 }} for group and role membership are required;
- authorized users of the system are specified;
- group and role membership are specified;
- access authorizations (i.e., privileges) are specified for each account;
- {{ insert: param, ac-02_odp.02 }} are specified for each account;
- approvals are required by {{ insert: param, ac-02_odp.03 }} for requests to create accounts;
- accounts are created in accordance with {{ insert: param, ac-02_odp.04 }};
- accounts are enabled in accordance with {{ insert: param, ac-02_odp.04 }};
- accounts are modified in accordance with {{ insert: param, ac-02_odp.04 }};
- accounts are disabled in accordance with {{ insert: param, ac-02_odp.04 }};
- accounts are removed in accordance with {{ insert: param, ac-02_odp.04 }};
- the use of accounts is monitored;
- account managers and {{ insert: param, ac-02_odp.05 }} are notified within {{ insert: param, ac-02_odp.06 }} when accounts are no longer required;
- account managers and {{ insert: param, ac-02_odp.05 }} are notified within {{ insert: param, ac-02_odp.07 }} when users are terminated or transferred;
- account managers and {{ insert: param, ac-02_odp.05 }} are notified within {{ insert: param, ac-02_odp.08 }} when system usage or the need to know changes for an individual;
- access to the system is authorized based on a valid access authorization;
- access to the system is authorized based on intended system usage;
- access to the system is authorized based on {{ insert: param, ac-02_odp.09 }};
- accounts are reviewed for compliance with account management requirements {{ insert: param, ac-02_odp.10 }};
- a process is established for changing shared or group account authenticators (if deployed) when individuals are removed from the group;
- a process is implemented for changing shared or group account authenticators (if deployed) when individuals are removed from the group;
- account management processes are aligned with personnel termination processes;
- account management processes are aligned with personnel transfer processes.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion