# AC-03 Access Enforcement

NIST SP 800-53 control. Family: AC Access Control. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
Guidance: Access control policies control access between active entities or subjects (i.e., users or processes acting on behalf of users) and passive entities or objects (i.e., devices, files, records, domains) in organizational systems. In addition to enforcing authorized access at the system level and recognizing that systems can host many applications and services in support of mission and business functions, access enforcement mechanisms can also be employed at the application and service level to provide increased information security and privacy. In contrast to logical access controls that are implemented within the system, physical access controls are addressed by the controls in the Physical and Environmental Protection (PE) family.

## Enhancements (13)
- AC-03(02) Dual Authorization
- AC-03(03) Mandatory Access Control
- AC-03(04) Discretionary Access Control
- AC-03(05) Security-relevant Information
- AC-03(07) Role-based Access Control
- AC-03(08) Revocation of Access Authorizations
- AC-03(09) Controlled Release
- AC-03(10) Audited Override of Access Control Mechanisms
- AC-03(11) Restrict Access to Specific Information Types
- AC-03(12) Assert and Enforce Application Access
- AC-03(13) Attribute-based Access Control
- AC-03(14) Individual Access. Baselines: privacy
- AC-03(15) Discretionary and Mandatory Access Control
Withdrawn by NIST: AC-03(01) (now in AC-06); AC-03(06) (now in MP-04 and SC-28).
Each enhancement's statement: /api/v1/controls/AC-03?fields=enhancements

## Patterns that use it (27)
- Critical (19): SP-001 Client Module; SP-002 Server Module; SP-004 SOA Publication and Location Pattern; SP-005 SOA Internal Service Usage Pattern; SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-013 Data Security Pattern; SP-022 Board of Directors Room; SP-023 Industrial Control Systems; SP-027 Secure LLM Usage; SP-028 Secure DevOps Pipeline Pattern; SP-029 Zero Trust Architecture; SP-030 API Security; SP-032 Modern Authentication; SP-044 SaaS Identity Lifecycle Management; SP-047 Secure Agentic AI Frameworks; SP-051 Tokenised Asset Security Architecture (draft); SP-053 Zero-Knowledge Proof Architecture (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (6): SP-033 Passkey Authentication; SP-037 Privileged User Management; SP-039 Client-Side Encryption and Data Privacy; SP-042 Third Party Risk Management; SP-050 Mobile Security Architecture (draft); SP-052 Decentralised Identity & Verifiable Credentials (draft)
- Standard (2): SP-020 Email Transport Layer Security (TLS) Pattern; SP-040 Post-Quantum Cryptography and Quantum Readiness

## Clauses by framework (84 frameworks)
- iso_27001_2022: A.5.15, A.5.33, A.8.3, A.8.4, A.8.18, A.8.20, A.8.26
- iso_27002_2022: 5.15, 8.3, 8.4
- cobit_2019: DSS05, DSS06
- pci_dss_v4: 1.2.8, 3.4, 7.2, 7.3
- nist_csf_2: PR.AA-05, PR.DS-01, PR.DS-10, PR.IR-01. OSA's own, not in NIST's crosswalk: PR.DS-01
- cis_controls_v8: CIS 3.3, CIS 6, CIS 6.7, CIS 6.8, CIS 13.9
- soc2_tsc: CC6.1, CC6.6, CC6.6-POF2
- finos_ccc: CCC-C05, CCC-C11
- iso_42001_2023: A.9.2, A.9.4
- iec_62443: 3-3 SR 2.1, 3-3 SR 4.1
- asd_e8: E8-8 ML3
- nis2: Art. 21(2)(i)
- apra_cps_234: Para 22-23
- mas_trm: 9, 15
- bsi_grundschutz: ORP.4, SYS.1.1, SYS.2.1
- anssi: Hygiene.14, Hygiene.15, Hygiene.17, SecNumCloud.10.3
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59), IV.B.d(60), IV.C(61)
- gdpr: Art.5(1)(f), Art.25(2), Art.32(1)(b)
- dora: Art.9(4)(c)
- bio2: 5.15, 8.3, 8.4
- rbi_csf: Annex1.8, ITGRCA.19
- fisc: FISC.T2, FISC.T5, FISC.T11
- lgpd_bcb: BCB.Art.3, BCB.OpenFinance, BCB.PIX, LGPD.Art.11, LGPD.Art.46
- hkma_tme1: TME1.8.1, TME1.10.3, TME1.11.2
- mlps_2: 8.1.3.2, 8.1.4.2, 8.2, 8.4, 8.5
- dnb_good_practice: DNB.12.3, DNB.17.2, DNB.20.1
- cra: CRA.I.2d
- swift_cscf: SWIFT.2.9, SWIFT.2.11A, SWIFT.5.1, SWIFT.5.4, SWIFT.6.3
- cbb_tm: TM-6
- cbuae: CR-4
- nca_ecc: 2-2, 2-7
- qatar_nia: AC
- sama_csf: 3.1
- uae_ia: T9
- bog_cisd: CISD-IX, CISD-VIII
- bom_ctrm: 3.3
- cbe_csf: CTO-1, CTO-5
- cbn_csf: Part3.2, Part5.2
- popia: s19
- sa_js2: JS2-7.1
- bcbs_239: Principle 11
- bot_cyber: Ch2.2
- cpmi_pfmi: CG.PR, PFMI.P17
- eba_ict: 3.4.2
- ecb_croe: CROE.2.3.1
- ffiec_is: II.C.7(b), II.C.13(a), II.C.15, II.C.15(a), II.C.15(b), II.C.18
- hipaa_sr: §164.308(a)(3)(i), §164.308(a)(3)(ii)(A), §164.308(a)(4)(i), §164.308(a)(4)(ii)(B), §164.308(a)(4)(ii)(C), §164.312(a)(1), §164.314(b)(2)
- iosco_cyber: PROT-1
- nydfs_500: 500.7
- sebi_cscrf: PR.AA
- cmmc_2: AC
- nerc_cip: CIP-007-6, CIP-011-3
- nrc_73_54: 73.54(c)(1), RG5.71-A-AC
- tsa_psd: SD-2 Sec B
- ieee_1686: 5.1, 5.9
- doe_c2m2: ACCESS
- api_1164: Sec 6
- awia: AWWA Sec 3
- iaea_nss: Sec 5.3
- cbest: CBEST.9
- tiber_eu: TIBER.CONF
- pci_hsm: 4, 8
- common_criteria: CC Part 2 — FDP
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.3
- fda_21_cfr_11: §11.10(d), §11.10(g)
- fda_cyber: SA-1, SA-4
- hitrust_csf: 01.a, 01.c, 13.e
- iso_27799: 9.1, 9.5, H.4
- lloyds_ms: MS1.1, MS2.1, MS5.1, MS6.1, MS8.3
- naic_ds: 4-access, 4B
- nhs_dspt: NDG-1.1, NDG-4.1
- pra_ss1_23: P3.3, P3.6, P-IT.1
- solvency_ii: DR.266-DataSec, EIOPA-ICT-4.4
- owasp_masvs_v2: MASVS-AUTH-1, MASVS-AUTH-3, MASVS-PLATFORM-1, MASVS-PRIVACY-1, MASVS-PRIVACY-4, MASVS-STORAGE-1
- csa_ccm_v4: DSP-17, IAM-16
- csa_aicm: DSP-17, IAM-16, MDS-07
- ccss_v9: 1.03.5, 1.05.1
- mica: Art.40(1), Art.55(1), Art.62(9), Art.63(1), Art.67(1), Art.97(1)
- basel_sco60: SCO60.61, SCO60.62, SCO60.66
- bssc: GSP-11, KMS-06, KMS-09, NOS-05, TIS-07
- sec_custody_digital: SEC-CD-02, SEC-CD-05
- dpdpa: Act.8(5), Act.11, Rules.6(1)(b), Rules.Sch1.B.3-4, Rules.Sch1.B.7, Rules.Sch2
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AC-03
- Clauses only: /api/v1/controls/AC-03?fields=mappings
- Page for people: /controls/ac-03/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
