# AC-09 Previous Logon Notification

NIST SP 800-53 control. Family: AC Access Control. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Notify the user, upon successful logon to the system, of the date and time of the last logon.
Guidance: Previous logon notification is applicable to system access via human user interfaces and access to systems that occurs in other types of architectures. Information about the last successful logon allows the user to recognize if the date and time provided is not consistent with the user’s last access.

## Enhancements (4)
- AC-09(01) Unsuccessful Logons
- AC-09(02) Successful and Unsuccessful Logons
- AC-09(03) Notification of Account Changes
- AC-09(04) Additional Logon Information
Each enhancement's statement: /api/v1/controls/AC-09?fields=enhancements

## Patterns that use it (2)
- Standard (2): SP-002 Server Module; SP-008 Public Web Server Pattern

## Clauses by framework (21 frameworks)
- iso_27001_2022: A.8.5
- cobit_2019: DSS05
- nist_csf_2: DE.CM-09
- nis2: Art. 21(2)(i)
- mas_trm: 9
- bsi_grundschutz: ORP.4
- anssi: Hygiene.29, SecNumCloud.13.7
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59)
- gdpr: Art.5(1)(f), Art.32(1)(d)
- dora: Art.10(1)
- qatar_nia: AC
- sama_csf: 3.1
- uae_ia: T9
- bom_ctrm: 3.3
- bot_cyber: Ch2.2
- ecb_croe: CROE.2.3.1
- ffiec_is: II.C.15
- iosco_cyber: PROT-1
- cmmc_2: AC
- hitrust_csf: 01.c
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AC-09
- Clauses only: /api/v1/controls/AC-09?fields=mappings
- Page for people: /controls/ac-09/
