πΌ AC-2 Account Management
- Contextual name: πΌ AC-2 Account Management
- ID:
/frameworks/nist-sp-800-53-r5/ac/02
- Located in: πΌ AC Access Control
Descriptionβ
a. Define and document the types of accounts allowed and specifically prohibited for use within the system; b. Assign account managers; c. Require [Assignment: organization-defined prerequisites and criteria] for group and role membership; d. Specify:
- Authorized users of the system;
- Group and role membership; and
- Access authorizations (i.e., privileges) and [Assignment: organization-defined attributes (as required)] for each account; e. Require approvals by [Assignment: organization-defined personnel or roles] for requests to create accounts; f. Create, enable, modify, disable, and remove accounts in accordance with [Assignment: organization-defined policy, procedures, prerequisites, and criteria]; g. Monitor the use of accounts; h. Notify account managers and [Assignment: organization-defined personnel or roles] within:
- [Assignment: organization-defined time period] when accounts are no longer required;
- [Assignment: organization-defined time period] when users are terminated or transferred; and
- [Assignment: organization-defined time period] when system usage or need-to-know changes for an individual; i. Authorize access to the system based on:
- A valid access authorization;
- Intended system usage; and
- [Assignment: organization-defined attributes (as required)]; j. Review accounts for compliance with account management requirements [Assignment: organization-defined frequency]; k. Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and l. Align account management processes with personnel termination and transfer processes.
Similarβ
- Sections
/frameworks/aws-fsbp-v1.0.0/dms/10
/frameworks/aws-fsbp-v1.0.0/eventbridge/03
/frameworks/aws-fsbp-v1.0.0/iam/01
/frameworks/aws-fsbp-v1.0.0/iam/02
/frameworks/aws-fsbp-v1.0.0/iam/08
/frameworks/aws-fsbp-v1.0.0/iam/21
/frameworks/aws-fsbp-v1.0.0/kms/01
/frameworks/aws-fsbp-v1.0.0/kms/02
- Internal
- ID:
dec-c-edf2e320
- ID:
Similar Sections (Take Policies From)β
Similar Sections (Give Policies To)β
Sub Sectionsβ
Policies (3)β
Policy | Logic Count | Flags |
---|---|---|
π AWS IAM Policy allows full administrative privileges π’ | 1 | π’ x6 |
π AWS IAM User has inline or directly attached policies π’ | 1 | π x1, π’ x5 |
π AWS IAM User with credentials unused for 45 days or more is not disabled π’ | 1 | π’ x6 |