Skip to main content
ControlFrame
Public source instrument

Authority and catalog facts only. No customer evidence is read, no assessment method is activated, and no control conclusion is recorded here.

Catalog context ≠ assessment result
Framework library

Catalog Observatory

NIST SP 800-53

Rev. 5, Release 5.2.0

Trace one authority signal through its exact source, normalized catalog, retained method context, and required human decision. The signal stops wherever the record stops.

Authority record
primary
Current edition
Rev. 5
Release
5.2.0
Published
Aug 27, 2025
Authority checked
Aug 26, 2026
Catalog reader
Release connected
NIST Computer Security Resource CenterSource-bound

Source-to-decision path

The provenance beam

Ends at named human acceptance
  1. Authority

    primary source · checked 2026-08-26Rev. 5, Release 5.2.0 is the registry's current edition.
  2. Source

    Source artifact boundExact release artifact · SHA-256 01f37cf90ea9…6e9bc062. Full digest remains visible below.
  3. Catalog

    1,196 catalog units indexedNormalized catalog · SHA-256 bfae171ee609…aaacbcc7.
  4. Reference method

    3,715 assessment-objective nodes retained · inactive2,931 method parts and 2,931 object parts are preserved for reference; no runnable test set is activated by this catalog reader.
  5. Human acceptance

    Required · no conclusion recordedThe reference method may prepare a review record. A named reviewer retains conclusion authority.

A later station can exist as configuration without inheriting the authority of an earlier one. Only a connected path carries provenance; only a named reviewer can accept a conclusion.

Observation coordinates

Select the record to inspect

Catalog units
1,196
controls + enhancements
Active
1,014
operative records
Withdrawn
182
retained lineage
Statements
1,016
source statements
Guidance
1,014
guidance entries
ODPs
1,600
organization-defined parameters

Catalog index

1,196 matching catalog units

Showing 50 of 1196
  1. AC-1ACPolicy and Proceduresactiveguidance9 ODPs1 assessment records
  2. AC-2ACAccount Managementactiveguidance10 ODPs1 assessment records
  3. AC-2(1)ACAutomated System Account Managementactiveguidance1 ODPs1 assessment records
  4. AC-2(2)ACAutomated Temporary and Emergency Account Managementactiveguidance2 ODPs1 assessment records
  5. AC-2(3)ACDisable Accountsactiveguidance2 ODPs1 assessment records
  6. AC-2(4)ACAutomated Audit Actionsactiveguidance1 assessment records
  7. AC-2(5)ACInactivity Logoutactiveguidance1 ODPs1 assessment records
  8. AC-2(6)ACDynamic Privilege Managementactiveguidance1 ODPs1 assessment records
  9. AC-2(7)ACPrivileged User Accountsactiveguidance1 ODPs1 assessment records
  10. AC-2(8)ACDynamic Account Managementactiveguidance1 ODPs1 assessment records
  11. AC-2(9)ACRestrictions on Use of Shared and Group Accountsactiveguidance1 ODPs1 assessment records
  12. AC-2(10)ACShared and Group Account Credential Changewithdrawn
  13. AC-2(11)ACUsage Conditionsactiveguidance2 ODPs1 assessment records
  14. AC-2(12)ACAccount Monitoring for Atypical Usageactiveguidance2 ODPs1 assessment records
  15. AC-2(13)ACDisable Accounts for High-risk Individualsactiveguidance2 ODPs1 assessment records
  16. AC-3ACAccess Enforcementactiveguidance1 assessment records
  17. AC-3(1)ACRestricted Access to Privileged Functionswithdrawn
  18. AC-3(2)ACDual Authorizationactiveguidance1 ODPs1 assessment records
  19. AC-3(3)ACMandatory Access Controlactiveguidance5 ODPs1 assessment records
  20. AC-3(4)ACDiscretionary Access Controlactiveguidance3 ODPs1 assessment records
  21. AC-3(5)ACSecurity-relevant Informationactiveguidance1 ODPs1 assessment records
  22. AC-3(6)ACProtection of User and System Informationwithdrawn
  23. AC-3(7)ACRole-based Access Controlactiveguidance3 ODPs1 assessment records
  24. AC-3(8)ACRevocation of Access Authorizationsactiveguidance1 ODPs1 assessment records
  25. AC-3(9)ACControlled Releaseactiveguidance3 ODPs1 assessment records
  26. AC-3(10)ACAudited Override of Access Control Mechanismsactiveguidance2 ODPs1 assessment records
  27. AC-3(11)ACRestrict Access to Specific Information Typesactiveguidance1 ODPs1 assessment records
  28. AC-3(12)ACAssert and Enforce Application Accessactiveguidance1 ODPs1 assessment records
  29. AC-3(13)ACAttribute-based Access Controlactiveguidance1 ODPs1 assessment records
  30. AC-3(14)ACIndividual Accessactiveguidance2 ODPs1 assessment records
  31. AC-3(15)ACDiscretionary and Mandatory Access Controlactiveguidance6 ODPs1 assessment records
  32. AC-4ACInformation Flow Enforcementactiveguidance1 ODPs1 assessment records
  33. AC-4(1)ACObject Security and Privacy Attributesactiveguidance11 ODPs1 assessment records
  34. AC-4(2)ACProcessing Domainsactiveguidance1 ODPs1 assessment records
  35. AC-4(3)ACDynamic Information Flow Controlactiveguidance1 ODPs1 assessment records
  36. AC-4(4)ACFlow Control of Encrypted Informationactiveguidance3 ODPs1 assessment records
  37. AC-4(5)ACEmbedded Data Typesactiveguidance1 ODPs1 assessment records
  38. AC-4(6)ACMetadataactiveguidance1 ODPs1 assessment records
  39. AC-4(7)ACOne-way Flow Mechanismsactiveguidance1 assessment records
  40. AC-4(8)ACSecurity and Privacy Policy Filtersactiveguidance10 ODPs1 assessment records
  41. AC-4(9)ACHuman Reviewsactiveguidance2 ODPs1 assessment records
  42. AC-4(10)ACEnable and Disable Security or Privacy Policy Filtersactiveguidance6 ODPs1 assessment records
  43. AC-4(11)ACConfiguration of Security or Privacy Policy Filtersactiveguidance3 ODPs1 assessment records
  44. AC-4(12)ACData Type Identifiersactiveguidance1 ODPs1 assessment records
  45. AC-4(13)ACDecomposition into Policy-relevant Subcomponentsactiveguidance1 ODPs1 assessment records
  46. AC-4(14)ACSecurity or Privacy Policy Filter Constraintsactiveguidance3 ODPs1 assessment records
  47. AC-4(15)ACDetection of Unsanctioned Informationactiveguidance4 ODPs1 assessment records
  48. AC-4(16)ACInformation Transfers on Interconnected Systemswithdrawn
  49. AC-4(17)ACDomain Authenticationactiveguidance1 ODPs1 assessment records
  50. AC-4(18)ACSecurity Attribute Bindingwithdrawn

The server returns at most 50 records per view. Refine the source query or family to inspect the remainder; the full catalog is never shipped to a browser bundle.

Field notebook · source record

AC-3(3)

Access Control
active

Mandatory Access Control

The statement below is source material, not a generated control summary.

01

Source statement

Enforce {{ insert: param, ac-3.3_prm_1 }} over the set of covered subjects and objects specified in the policy, and where the policy: Is uniformly enforced across the covered subjects and objects within the system; Specifies that a subject that has been granted access to information is constrained from doing any of the following; Passing the information to unauthorized subjects or objects; Granting its privileges to other subjects; Changing one or more security attributes (specified by the policy) on subjects, objects, the system, or system components; Choosing the security attributes and attribute values (specified by the policy) to be associated with newly created or modified objects; and Changing the rules governing access control; and Specifies that {{ insert: param, ac-03.03_odp.03 }} may explicitly be granted {{ insert: param, ac-03.03_odp.04 }} such that they are not limited by any defined subset (or all) of the above constraints.

02

Guidance

Mandatory access control is a type of nondiscretionary access control. Mandatory access control policies constrain what actions subjects can take with information obtained from objects for which they have already been granted access. This prevents the subjects from passing the information to unauthorized subjects and objects. Mandatory access control policies constrain actions that subjects can take with respect to the propagation of access control privileges; that is, a subject with a privilege cannot pass that privilege to other subjects. The policy is uniformly enforced over all subjects and objects to which the system has control. Otherwise, the access control policy can be circumvented. This enforcement is provided by an implementation that meets the reference monitor concept as described in [AC-25](#ac-25) . The policy is bounded by the system (i.e., once the information is passed outside of the control of the system, additional means may be required to ensure that the constraints on the information remain in effect). The trusted subjects described above are granted privileges consistent with the concept of least privilege (see [AC-6](#ac-6) ). Trusted subjects are only given the minimum privileges necessary for satisfying organizational mission/business needs relative to the above policy. The control is most applicable when there is a mandate that establishes a policy regarding access to controlled unclassified information or classified information and some users of the system are not authorized access to all such information resident in the system. Mandatory access control can operate in conjunction with discretionary access control as described in [AC-3(4)](#ac-3.4) . A subject constrained in its operation by mandatory access control policies can still operate under the less rigorous constraints of AC-3(4), but mandatory access control policies take precedence over the less rigorous constraints of AC-3(4). For example, while a mandatory access control policy imposes a constraint that prevents a subject from passing information to another subject operating at a different impact or classification level, AC-3(4) permits the subject to pass the information to any other subject with the same impact or classification level as the subject. Examples of mandatory access control policies include the Bell-LaPadula policy to protect confidentiality of information and the Biba policy to protect the integrity of information.

03

Organization-defined parameters

Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.

ac-3.3_prm_1

organization-defined mandatory access control policy

ac-03.03_odp.01

mandatory access control policy

Source guidance
  • mandatory access control policy enforced over the set of covered subjects is defined;
ac-03.03_odp.02

mandatory access control policy

Source guidance
  • mandatory access control policy enforced over the set of covered objects is defined;
ac-03.03_odp.03

subjects

Source guidance
  • subjects to be explicitly granted privileges are defined;
ac-03.03_odp.04

privileges

Source guidance
  • privileges to be explicitly granted to subjects are defined;
04

Assessment reference context

Retained, not activated.1 source assessment records and 10 objective nodes are available as reference context. This surface runs none of them.

ac-3.3_objAC-03(03)10 objective nodes
  1. {{ insert: param, ac-03.03_odp.01 }} is enforced over the set of covered subjects specified in the policy;
  2. {{ insert: param, ac-03.03_odp.02 }} is enforced over the set of covered objects specified in the policy;
  3. {{ insert: param, ac-03.03_odp.01 }} is uniformly enforced across the covered subjects within the system;
  4. {{ insert: param, ac-03.03_odp.02 }} is uniformly enforced across the covered objects within the system;
  5. {{ insert: param, ac-03.03_odp.01 }} and {{ insert: param, ac-03.03_odp.02 }} specifying that a subject that has been granted access to information is constrained from passing the information to unauthorized subjects or objects are enforced;
  6. {{ insert: param, ac-03.03_odp.01 }} and {{ insert: param, ac-03.03_odp.02 }} specifying that a subject that has been granted access to information is constrained from granting its privileges to other subjects are enforced;
  7. {{ insert: param, ac-03.03_odp.01 }} and {{ insert: param, ac-03.03_odp.02 }} specifying that a subject that has been granted access to information is constrained from changing one of more security attributes (specified by the policy) on subjects, objects, the system, or system components are enforced;
  8. {{ insert: param, ac-03.03_odp.01 }} and {{ insert: param, ac-03.03_odp.02 }} specifying that a subject that has been granted access to information is constrained from choosing the security attributes and attribute values (specified by the policy) to be associated with newly created or modified objects are enforced;
  9. {{ insert: param, ac-03.03_odp.01 }} and {{ insert: param, ac-03.03_odp.02 }} specifying that a subject that has been granted access to information is constrained from changing the rules governing access control are enforced;
  10. {{ insert: param, ac-03.03_odp.01 }} and {{ insert: param, ac-03.03_odp.02 }} specifying that {{ insert: param, ac-03.03_odp.03 }} may explicitly be granted {{ insert: param, ac-03.03_odp.04 }} such that they are not limited by any defined subset (or all) of the above constraints are enforced.
05

Reference method and authority

  1. InputExact release, source digest, control ID, and cited source fields
  2. Agent taskPrepare a bounded evidence request or test-plan draft
  3. Fail closedAbstain when source, scope, or assessment identity is missing
  4. Human acceptanceA named reviewer decides whether evidence supports the conclusion

Release identity

Source and normalized digests

Source artifact
data/frameworks/catalogs/nist-sp-800-53-rev5/5.2.0/source/NIST_SP-800-53_rev5_catalog.json.gz
Source SHA-256
01f37cf90ea99d92242c936cbfbdebcc338eef1f71454e2acac36cc56e9bc062
Catalog SHA-256
bfae171ee60951925f14cf5fc01c7749ce9d94e5ce65ffa68966374caaacbcc7
Assessment activation
Retained only · inactive
Assessment reference corpus
1,014 objective sets · 3,715 objective nodes · 2,787 with prose
Method and object context
2,931 method parts · 2,931 object parts
Inspect NIST OSCAL Content v1.5.0 · OSCAL 1.2.2 (opens in a new tab)
Catalog Observatory: framework explorer | ControlFrame