Skip to main content

💼 AC-2(1) Automated System Account Management (M)(H)

  • ID: /frameworks/fedramp-high-security-controls/ac/02/01

Description

Support the management of system accounts using [Assignment: organization-defined automated mechanisms].

Similar

  • Sections
    • /frameworks/nist-sp-800-53-r5/ac/02/01
  • Internal
    • ID: dec-c-3dc09811

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST SP 800-53 Revision 5 → 💼 AC-2(1) Account Management _ Automated System Account Management418no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 FedRAMP Moderate Security Controls → 💼 AC-2(1) Automated System Account Management (M)(H)18no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (18)

PolicyLogic CountFlagsCompliance
🛡️ AWS Account IAM Password Policy minimum password length is 14 characters or less🟢1🟢 x6no data
🛡️ AWS Account IAM Password Policy Number of passwords to remember is not set to 24🟢1🟢 x6no data
🛡️ AWS Account Root User has active access keys🟢1🟢 x6no data
🛡️ AWS Account Root User Hardware MFA is not enabled.🟢⚪🟢 x2, ⚪ x1no data
🛡️ AWS Account Root User MFA is not enabled.🟢1🟢 x6no data
🛡️ AWS IAM Policy allows full administrative privileges🟢1🟢 x6no data
🛡️ AWS IAM User Access Keys are not rotated every 90 days or less🟢1🟢 x6no data
🛡️ AWS IAM User has inline or directly attached policies🟢1🟠 x1, 🟢 x5no data
🛡️ AWS IAM User MFA is not enabled for all users with console password🟢1🟢 x6no data
🛡️ AWS IAM User with credentials unused for 45 days or more is not disabled🟢1🟢 x6no data
🛡️ AWS Secrets Manager Secret Automatic Rotation is not enabled🟢1🟢 x6no data
🛡️ Azure App Service is not registered with Microsoft Entra ID🟢1🟢 x6no data
🛡️ Azure Non-RBAC Key Vault stores Keys without expiration date🟢1🟢 x6no data
🛡️ Azure Non-RBAC Key Vault stores Secrets without expiration date🟢1🟢 x6no data
🛡️ Azure RBAC Key Vault stores Keys without expiration date🟢1🟢 x6no data
🛡️ Azure RBAC Key Vault stores Secrets without expiration date🟢1🟢 x6no data
🛡️ Azure SQL Database Transparent Data Encryption is not enabled🟢1🟢 x6no data
🛡️ Azure SQL Server Microsoft Entra authentication is not configured🟢1🟢 x6no data