Field notebook · source record
AC-3(10)
Access ControlAudited Override of Access Control Mechanisms
The statement below is source material, not a generated control summary.
Source statement
Employ an audited override of automated access control mechanisms under {{ insert: param, ac-03.10_odp.01 }} by {{ insert: param, ac-03.10_odp.02 }}.
Guidance
In certain situations, such as when there is a threat to human life or an event that threatens the organization’s ability to carry out critical missions or business functions, an override capability for access control mechanisms may be needed. Override conditions are defined by organizations and used only in those limited circumstances. Audit events are defined in [AU-2](#au-2) . Audit records are generated in [AU-12](#au-12).
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-03.10_odp.01
conditions
Source guidance- conditions under which to employ an audited override of automated access control mechanisms are defined;
- ac-03.10_odp.02
roles
Source guidance- roles allowed to employ an audited override of automated access control mechanisms are defined;
Assessment reference context
Retained, not activated.1 source assessment records and 1 objective nodes are available as reference context. This surface runs none of them.
ac-3.10_objAC-03(10)1 objective nodes
- an audited override of automated access control mechanisms is employed under {{ insert: param, ac-03.10_odp.01 }} by {{ insert: param, ac-03.10_odp.02 }}.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion