Skip to main content

πŸ’Ό AC-16 Security and Privacy Attributes

  • Contextual name: πŸ’Ό AC-16 Security and Privacy Attributes
  • ID: /frameworks/nist-sp-800-53-r5/ac/16
  • Located in: πŸ’Ό AC Access Control

Description​

a. Provide the means to associate [Assignment: organization-defined types of security and privacy attributes] with [Assignment: organization-defined security and privacy attribute values] for information in storage, in process, and/or in transmission; b. Ensure that the attribute associations are made and retained with the information; c. Establish the following permitted security and privacy attributes from the attributes defined in AC-16a for [Assignment: organization-defined systems]: [Assignment: organization-defined security and privacy attributes]; d. Determine the following permitted attribute values or ranges for each of the established attributes: [Assignment: organization-defined attribute values or ranges for established attributes]; e. Audit changes to attributes; and f. Review [Assignment: organization-defined security and privacy attributes] for applicability [Assignment: organization-defined frequency].

Similar​

  • Internal
    • ID: dec-c-7d35ae35

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties58

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό AC-16(1) Security and Privacy Attributes _ Dynamic Attribute Association
πŸ’Ό AC-16(2) Security and Privacy Attributes _ Attribute Value Changes by Authorized Individuals
πŸ’Ό AC-16(3) Security and Privacy Attributes _ Maintenance of Attribute Associations by System
πŸ’Ό AC-16(4) Security and Privacy Attributes _ Association of Attributes by Authorized Individuals
πŸ’Ό AC-16(5) Security and Privacy Attributes _ Attribute Displays on Objects to Be Output
πŸ’Ό AC-16(6) Security and Privacy Attributes _ Maintenance of Attribute Association
πŸ’Ό AC-16(7) Security and Privacy Attributes _ Consistent Attribute Interpretation
πŸ’Ό AC-16(8) Security and Privacy Attributes _ Association Techniques and Technologies
πŸ’Ό AC-16(9) Security and Privacy Attributes _ Attribute Reassignment β€” Regrading Mechanisms
πŸ’Ό AC-16(10) Security and Privacy Attributes _ Attribute Configuration by Authorized Individuals