Skip to main content

💼 AC-24 ACCESS CONTROL DECISIONS

  • ID: /frameworks/nist-sp-800-53-r4/ac/24

Description​

The organization establishes procedures to ensure [Assignment: organization-defined access control decisions] are applied to each access request prior to access enforcement.

Similar​

  • Internal
    • ID: dec-c-32553a53

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties1756no data
💼 NIST CSF v1.1 → 💼 PR.AC-6: Identities are proofed and bound to credentials and asserted in interactions413no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 AC-24 (1) TRANSMIT ACCESS AUTHORIZATION INFORMATIONno data
💼 AC-24 (2) NO USER OR PROCESS IDENTITYno data