Field notebook · source record
AC-2(3)
Access ControlDisable Accounts
The statement below is source material, not a generated control summary.
Source statement
Disable accounts within {{ insert: param, ac-02.03_odp.01 }} when the accounts: Have expired; Are no longer associated with a user or individual; Are in violation of organizational policy; or Have been inactive for {{ insert: param, ac-02.03_odp.02 }}.
Guidance
Disabling expired, inactive, or otherwise anomalous accounts supports the concepts of least privilege and least functionality which reduce the attack surface of the system.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-02.03_odp.01
time period
Source guidance- time period within which to disable accounts is defined;
- ac-02.03_odp.02
time period
Source guidance- time period for account inactivity before disabling is defined;
Assessment reference context
Retained, not activated.1 source assessment records and 4 objective nodes are available as reference context. This surface runs none of them.
ac-2.3_objAC-02(03)4 objective nodes
- accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts have expired;
- accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts are no longer associated with a user or individual;
- accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts are in violation of organizational policy;
- accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts have been inactive for {{ insert: param, ac-02.03_odp.02 }}.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion