Field notebook · source record
AC-3(12)
Access ControlAssert and Enforce Application Access
The statement below is source material, not a generated control summary.
Source statement
Require applications to assert, as part of the installation process, the access needed to the following system applications and functions: {{ insert: param, ac-03.12_odp }}; Provide an enforcement mechanism to prevent unauthorized access; and Approve access changes after initial installation of the application.
Guidance
Asserting and enforcing application access is intended to address applications that need to access existing system applications and functions, including user contacts, global positioning systems, cameras, keyboards, microphones, networks, phones, or other files.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-03.12_odp
system applications and functions
Source guidance- system applications and functions requiring access assertion are defined;
Assessment reference context
Retained, not activated.1 source assessment records and 3 objective nodes are available as reference context. This surface runs none of them.
ac-3.12_objAC-03(12)3 objective nodes
- as part of the installation process, applications are required to assert the access needed to the following system applications and functions: {{ insert: param, ac-03.12_odp }};
- an enforcement mechanism to prevent unauthorized access is provided;
- access changes after initial installation of the application are approved.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion