← Controls / AC

AC-09 Previous Logon Notification

Access Control

Description

Notify the user, upon successful logon to the system, of the date and time of the last logon.

Supplemental Guidance

Previous logon notification is applicable to system access via human user interfaces and access to systems that occurs in other types of architectures. Information about the last successful logon allows the user to recognize if the date and time provided is not consistent with the user’s last access.

Enhancements (4)

What NIST adds to this control. Select one to read its statement.

AC-09(01) Unsuccessful Logons

Notify the user, upon successful logon, of the number of unsuccessful logon attempts since the last successful logon.

AC-09(02) Successful and Unsuccessful Logons

Notify the user, upon successful logon, of the number of [Selection (one): successful logons; unsuccessful logon attempts; both] during [Assignment: organization-defined time period].

AC-09(03) Notification of Account Changes

Notify the user, upon successful logon, of changes to [Assignment: organization-defined security-related characteristics or parameters of the user’s account] during [Assignment: organization-defined time period].

AC-09(04) Additional Logon Information

Notify the user, upon successful logon, of the following additional information: [Assignment: organization-defined additional information].

Patterns that use this control (2)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.8.5

COBIT 2019

DSS05

NIST CSF 2.0

DE.CM-09

NIS2 Directive

Art. 21(2)(i)

MAS TRM

9

BSI IT-Grundschutz

ORP.4

ANSSI

Hygiene.29SecNumCloud.13.7

FINMA Circular 2023/1

IV.B.d(59)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)Art.32(1)(d)

EU DORA

Art.10(1)

SAMA CSF

3.1

UAE IA

T9

Qatar NIA

AC

BoM CTRM

3.3

IOSCO Cyber Resilience

PROT-1

FFIEC IS

II.C.15

ECB CROE

CROE.2.3.1

BOT Cyber Resilience

Ch2.2

CMMC 2.0

AC

HITRUST CSF v11

01.c

ISO 17799 (legacy)

11.5.1

COBIT 4.1 (legacy)

None.