← Controls / AC

AC-02 Account Management

Access Control

Low Moderate High

Description

a. Define and document the types of accounts allowed and specifically prohibited for use within the system; b. Assign account managers; c. Require [Assignment: organization-defined prerequisites and criteria] for group and role membership; d. Specify: 1. Authorized users of the system; 2. Group and role membership; and 3. Access authorizations (i.e., privileges) and [Assignment: organization-defined attributes (as required)] for each account; e. Require approvals by [Assignment: organization-defined personnel or roles] for requests to create accounts; f. Create, enable, modify, disable, and remove accounts in accordance with [Assignment: organization-defined policy, procedures, prerequisites, and criteria]; g. Monitor the use of accounts; h. Notify account managers and [Assignment: organization-defined personnel or roles] within: 1. [Assignment: organization-defined time period] when accounts are no longer required; 2. [Assignment: organization-defined time period] when users are terminated or transferred; and 3. [Assignment: organization-defined time period] when system usage or need-to-know changes for an individual; i. Authorize access to the system based on: 1. A valid access authorization; 2. Intended system usage; and 3. [Assignment: organization-defined attributes (as required)]; j. Review accounts for compliance with account management requirements [Assignment: organization-defined frequency]; k. Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and l. Align account management processes with personnel termination and transfer processes.

Supplemental Guidance

Examples of system account types include individual, shared, group, system, guest, anonymous, emergency, developer, temporary, and service. Identification of authorized system users and the specification of access privileges reflect the requirements in other controls in the security plan. Users requiring administrative privileges on system accounts receive additional scrutiny by organizational personnel responsible for approving such accounts and privileged access, including system owner, mission or business owner, senior agency information security officer, or senior agency official for privacy. Types of accounts that organizations may wish to prohibit due to increased risk include shared, group, emergency, anonymous, temporary, and guest accounts. Where access involves personally identifiable information, security programs collaborate with the senior agency official for privacy to establish the specific conditions for group and role membership; specify authorized users, group and role membership, and access authorizations for each account; and create, adjust, or remove system accounts in accordance with organizational policies. Policies can include such information as account expiration dates or other factors that trigger the disabling of accounts. Organizations may choose to define access privileges or other attributes by account, type of account, or a combination of the two. Examples of other attributes required for authorizing access include restrictions on time of day, day of week, and point of origin. In defining other system account attributes, organizations consider system-related requirements and mission/business requirements. Failure to consider these factors could affect system availability. Temporary and emergency accounts are intended for short-term use. Organizations establish temporary accounts as part of normal account activation procedures when there is a need for short-term accounts without the demand for immediacy in account activation. Organizations establish emergency accounts in response to crisis situations and with the need for rapid account activation. Therefore, emergency account activation may bypass normal account authorization processes. Emergency and temporary accounts are not to be confused with infrequently used accounts, including local logon accounts used for special tasks or when network resources are unavailable (may also be known as accounts of last resort). Such accounts remain available and are not subject to automatic disabling or removal dates. Conditions for disabling or deactivating accounts include when shared/group, emergency, or temporary accounts are no longer required and when individuals are transferred or terminated. Changing shared/group authenticators when members leave the group is intended to ensure that former group members do not retain access to the shared or group account. Some types of system accounts may require specialized training.

Changes from Rev 4

Removes parameter for system account types Adds prerequisite and criteria parameter for group and role membership Adds access authorizations parameter for attributes (as required) for each account Adds parameters to notify account managers and organization-defined personnel or roles within time-period when accounts are no longer required; when users are terminated or transferred; and when system usage or need-to-know changes for an individual Adds control text with a new parameter requiring authorize access to the system based on a valid access authorization, intended system usage; and attributes (as required) Adds control text requiring alignment of account management processes with personnel termination and transfer processes Incorporates withdrawn control AC-02(10)

Enhancements (12)

What NIST adds to this control. Select one to read its statement.

AC-02(01) Automated System Account Management ModerateHigh

Support the management of system accounts using [Assignment: organization-defined automated mechanisms].

AC-02(02) Automated Temporary and Emergency Account Management ModerateHigh

Automatically [Selection (one): remove; disable] temporary and emergency accounts after [Assignment: organization-defined time period for each type of account].

AC-02(03) Disable Accounts ModerateHigh

Disable accounts within [Assignment: organization-defined time period] when the accounts: a. Have expired; b. Are no longer associated with a user or individual; c. Are in violation of organizational policy; or d. Have been inactive for [Assignment: organization-defined time period].

AC-02(04) Automated Audit Actions ModerateHigh

Automatically audit account creation, modification, enabling, disabling, and removal actions.

AC-02(05) Inactivity Logout ModerateHigh

Require that users log out when [Assignment: organization-defined time period of expected inactivity or description of when to log out].

AC-02(06) Dynamic Privilege Management

Implement [Assignment: organization-defined dynamic privilege management capabilities].

AC-02(07) Privileged User Accounts

a. Establish and administer privileged user accounts in accordance with [Selection (one): a role-based access scheme; an attribute-based access scheme]; b. Monitor privileged role or attribute assignments; c. Monitor changes to roles or attributes; and d. Revoke access when privileged role or attribute assignments are no longer appropriate.

AC-02(08) Dynamic Account Management

Create, activate, manage, and deactivate [Assignment: organization-defined system accounts] dynamically.

AC-02(09) Restrictions on Use of Shared and Group Accounts

Only permit the use of shared and group accounts that meet [Assignment: organization-defined conditions for establishing shared and group accounts].

AC-02(11) Usage Conditions High

Enforce [Assignment: organization-defined circumstances and/or usage conditions] for [Assignment: organization-defined system accounts].

AC-02(12) Account Monitoring for Atypical Usage High

a. Monitor system accounts for [Assignment: organization-defined atypical usage]; and b. Report atypical usage of system accounts to [Assignment: organization-defined personnel or roles].

AC-02(13) Disable Accounts for High-risk Individuals ModerateHigh

Disable accounts of individuals within [Assignment: organization-defined time period] of discovery of [Assignment: organization-defined significant risks].

Withdrawn by NIST:

  • AC-02(10) Shared and Group Account Credential Change, now in AC-02

MITRE ATT&CK Techniques (220)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Initial Access 8 Execution 29 Persistence 61 Privilege Escalation 53 Defense Evasion 80 Credential Access 43 Discovery 7 Lateral Movement 17 Collection 11 Exfiltration 9 Impact 4
Show all 220 techniques grouped by tactic

Persistence

T1053 T1078 T1098 T1136 T1197 T1505 T1525 T1542 T1543 T1546 T1556 T1574 T1053.002 T1053.003 T1053.005 T1053.006 T1053.007 T1078.001 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.005 T1098.006 T1098.007 T1136.001 T1136.002 T1136.003 T1505.002 T1505.003 T1505.005 T1542.001 T1542.003 T1542.005 T1543.001 T1543.002 T1543.003 T1543.004 T1543.005 T1546.003 T1547.004 T1547.006 T1547.009 T1547.012 T1547.013 T1556.001 T1556.003 T1556.004 T1556.005 T1556.006 T1556.007 T1556.009 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.012

Privilege Escalation

T1053 T1055 T1068 T1078 T1098 T1134 T1484 T1543 T1546 T1548 T1574 T1611 T1053.002 T1053.003 T1053.005 T1053.006 T1053.007 T1055.008 T1078.001 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.005 T1098.006 T1098.007 T1134.001 T1134.002 T1134.003 T1543.001 T1543.002 T1543.003 T1543.004 T1543.005 T1546.003 T1547.004 T1547.006 T1547.009 T1547.012 T1547.013 T1548.002 T1548.003 T1548.005 T1548.006 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.012

Defense Evasion

T1036 T1055 T1070 T1078 T1134 T1197 T1218 T1222 T1484 T1542 T1548 T1550 T1553 T1556 T1562 T1574 T1578 T1599 T1601 T1610 T1612 T1036.003 T1036.005 T1036.010 T1055.008 T1070.001 T1070.002 T1070.003 T1070.007 T1070.008 T1070.009 T1078.001 T1078.002 T1078.003 T1078.004 T1134.001 T1134.002 T1134.003 T1218.007 T1218.015 T1222.001 T1222.002 T1542.001 T1542.003 T1542.005 T1548.002 T1548.003 T1548.005 T1548.006 T1550.002 T1550.003 T1556.001 T1556.003 T1556.004 T1556.005 T1556.006 T1556.007 T1556.009 T1562.001 T1562.002 T1562.004 T1562.006 T1562.007 T1562.008 T1562.009 T1562.012 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.012 T1578.001 T1578.002 T1578.003 T1578.005 T1599.001 T1601.001 T1601.002

Credential Access

Compliance Mappings

ISO 27001:2022

A.5.15A.5.16A.5.18A.8.2

ISO 27002:2022

5.155.188.2

COBIT 2019

DSS05

CIS Controls v8

CIS 4.7CIS 5CIS 5.1CIS 5.3CIS 5.5CIS 5.6CIS 6CIS 6.1CIS 6.2CIS 6.6CIS 6.7CIS 6.8CIS 12.5

NIST CSF 2.0

DE.CM-01DE.CM-03PR.AA-01PR.AA-05PR.DS-10

SOC 2 TSC

CC6.1CC6.6CC6.6-POF2

PCI DSS v4.0.1

2.2.12.2.27.28.28.6

CSA CCM v4

IAM-03IAM-05IAM-06IAM-07IAM-08IAM-10IAM-11IAM-13LOG-12

CSA AICM v1

IAM-03IAM-05IAM-06IAM-07IAM-08IAM-10IAM-11IAM-13IAM-17IAM-18LOG-12

FINOS CCC

CCC-C11

ISO 42001:2023

A.3.2

IEC 62443

3-3 SR 1.3

NIS2 Directive

Art. 21(2)(i)

MAS TRM

9

APRA CPS 234

Para 22-23

ASD Essential Eight

E8-5E8-5 ML1E8-5 ML2E8-5 ML3

BSI IT-Grundschutz

OPS.1.1.2ORP.4

ANSSI

Hygiene.6Hygiene.7Hygiene.11Hygiene.13Hygiene.32SecNumCloud.10.2

FINMA Circular 2023/1

IV.B.d(59)IV.B.d(60)IV.C(61)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)Art.25(2)Art.32(1)(b)Art.32(4)

EU DORA

Art.9(4)(c)Art.9(4)(d)

BIO2

5.155.188.2

RBI CSF

Annex1.8ITGRCA.19

FISC Security Guidelines

FISC.T2

LGPD + BCB 4893

BCB.Art.3BCB.PIXLGPD.Art.46

HKMA TM-E-1

TME1.8.1TME1.8.2

MLPS 2.0

8.1.4.28.1.7.2

DNB Good Practice

DNB.8.5DNB.17.2

EU CRA

CRA.I.2d

SWIFT CSCF

SWIFT.1.2SWIFT.2.11ASWIFT.5.1

SAMA CSF

3.1

NCA ECC

2-2

UAE IA

T9

CBB TM

TM-6

Qatar NIA

AC

CBUAE

CR-4

CBE CSF

CD-1CTO-1

SA JS2

JS2-7.1

CBN CSF

Part3.2

BoG CISD

CISD-IXCISD-VIII

POPIA

s19

BoM CTRM

3.3

IOSCO Cyber Resilience

PROT-1

BCBS 239

Principle 11

CPMI-IOSCO PFMI

CG.PRPFMI.P17

FFIEC IS

II.C.7II.C.7(b)II.C.15

NYDFS 500

500.7

HIPAA Security Rule

§164.308(a)(3)(i)§164.308(a)(3)(ii)(A)§164.308(a)(3)(ii)(B)§164.308(a)(3)(ii)(C)§164.308(a)(4)(i)§164.308(a)(4)(ii)(B)§164.308(a)(4)(ii)(C)§164.312(a)(1)§164.312(a)(2)(i)§164.312(a)(2)(ii)

ECB CROE

CROE.2.3.1

EBA ICT Guidelines

3.4.2

SEBI CSCRF

PR.AA

BOT Cyber Resilience

Ch2.2Ch8.2

CMMC 2.0

AC

NERC CIP

CIP-004-7CIP-007-6

10 CFR 73.54

RG5.71-A-AC

TSA Pipeline SD

SD-2 Sec B

IEEE 1686-2022

5.1

FERC CIP Orders

Order 850

DOE C2M2 v2.1

ACCESS

API 1164

Sec 6

AWIA

AWWA Sec 3

IAEA NSS 17-T

Sec 5.2Sec 5.3

FIPS 140-3

FIPS 140-3 §7.4

Common Criteria

CC Part 2 — FMT

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.4

Lloyd's Minimum Standards

MS8.3

NAIC Insurance Data Security

4-access4B

PRA SS1/23

P2.4P-IT.1

FCA SYSC 13

SYSC 13.7.3

HITRUST CSF v11

01.a02.c

FDA 21 CFR Part 11

§11.10(d)§11.10(g)§11.100(a)§11.200(a)(2)§11.300(a)§11.300(b)§11.300(c)

FDA Cybersecurity Guidance

SA-1

ISO 27799

7.39.19.29.3

NHS DSPT

NDG-4.1NDG-4.2

CCSS v9.0

1.04.11.04.21.06.2

MiCA

Art.67(1)Art.86(1)

Basel SCO60

SCO60.55SCO60.62

BSSC Standards

GSP-11KMS-06NOS-05

SEC Custody (Digital Assets)

SEC-CD-02SEC-CD-05SEC-CD-16

India DPDPA

Rules.6(1)(b)

ISO 17799 (legacy)

6.2.26.2.38.3.311.2.111.2.211.2.411.7.2

COBIT 4.1 (legacy)

DS5.4