← Controls / AC

AC-03 Access Enforcement

Access Control

Low Moderate High

Description

Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

Supplemental Guidance

Access control policies control access between active entities or subjects (i.e., users or processes acting on behalf of users) and passive entities or objects (i.e., devices, files, records, domains) in organizational systems. In addition to enforcing authorized access at the system level and recognizing that systems can host many applications and services in support of mission and business functions, access enforcement mechanisms can also be employed at the application and service level to provide increased information security and privacy. In contrast to logical access controls that are implemented within the system, physical access controls are addressed by the controls in the Physical and Environmental Protection (PE) family.

Enhancements (13)

What NIST adds to this control. Select one to read its statement.

AC-03(02) Dual Authorization

Enforce dual authorization for [Assignment: organization-defined privileged commands and/or other organization-defined actions].

AC-03(03) Mandatory Access Control

Enforce [Assignment: organization-defined mandatory access control policy] over the set of covered subjects and objects specified in the policy, and where the policy: a. Is uniformly enforced across the covered subjects and objects within the system; b. Specifies that a subject that has been granted access to information is constrained from doing any of the following; 1. Passing the information to unauthorized subjects or objects; 2. Granting its privileges to other subjects; 3. Changing one or more security attributes (specified by the policy) on subjects, objects, the system, or system components; 4. Choosing the security attributes and attribute values (specified by the policy) to be associated with newly created or modified objects; and 5. Changing the rules governing access control; and c. Specifies that [Assignment: organization-defined subjects] may explicitly be granted [Assignment: organization-defined privileges] such that they are not limited by any defined subset (or all) of the above constraints.

AC-03(04) Discretionary Access Control

Enforce [Assignment: organization-defined discretionary access control policy] over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information can do one or more of the following: a. Pass the information to any other subjects or objects; b. Grant its privileges to other subjects; c. Change security attributes on subjects, objects, the system, or the system’s components; d. Choose the security attributes to be associated with newly created or revised objects; or e. Change the rules governing access control.

AC-03(05) Security-relevant Information

Prevent access to [Assignment: organization-defined security-relevant information] except during secure, non-operable system states.

AC-03(07) Role-based Access Control

Enforce a role-based access control policy over defined subjects and objects and control access based upon [Assignment: organization-defined roles and users authorized to assume such roles].

AC-03(08) Revocation of Access Authorizations

Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on [Assignment: organization-defined rules governing the timing of revocations of access authorizations].

AC-03(09) Controlled Release

Release information outside of the system only if: a. The receiving [Assignment: organization-defined system or system component] provides [Assignment: organization-defined controls]; and b. [Assignment: organization-defined controls] are used to validate the appropriateness of the information designated for release.

AC-03(10) Audited Override of Access Control Mechanisms

Employ an audited override of automated access control mechanisms under [Assignment: organization-defined conditions] by [Assignment: organization-defined roles].

AC-03(11) Restrict Access to Specific Information Types

Restrict access to data repositories containing [Assignment: organization-defined information types].

AC-03(12) Assert and Enforce Application Access

a. Require applications to assert, as part of the installation process, the access needed to the following system applications and functions: [Assignment: organization-defined system applications and functions]; b. Provide an enforcement mechanism to prevent unauthorized access; and c. Approve access changes after initial installation of the application.

AC-03(13) Attribute-based Access Control

Enforce attribute-based access control policy over defined subjects and objects and control access based upon [Assignment: organization-defined attributes to assume access permissions].

AC-03(14) Individual Access Privacy

Provide [Assignment: organization-defined mechanisms] to enable individuals to have access to the following elements of their personally identifiable information: [Assignment: organization-defined elements].

AC-03(15) Discretionary and Mandatory Access Control

a. Enforce [Assignment: organization-defined mandatory access control policy] over the set of covered subjects and objects specified in the policy; and b. Enforce [Assignment: organization-defined discretionary access control policy] over the set of covered subjects and objects specified in the policy.

Withdrawn by NIST:

  • AC-03(01) Restricted Access to Privileged Functions, now in AC-06
  • AC-03(06) Protection of User and System Information, now in MP-04 and SC-28

MITRE ATT&CK Techniques (281)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Initial Access 10 Execution 29 Persistence 76 Privilege Escalation 64 Defense Evasion 91 Credential Access 48 Discovery 7 Lateral Movement 20 Collection 21 Command & Control 8 Exfiltration 10 Impact 23
Show all 281 techniques grouped by tactic

Persistence

T1037 T1053 T1078 T1098 T1133 T1136 T1197 T1205 T1505 T1525 T1542 T1543 T1546 T1556 T1574 T1037.002 T1037.003 T1037.004 T1037.005 T1053.002 T1053.003 T1053.005 T1053.006 T1053.007 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.004 T1098.005 T1098.006 T1098.007 T1136.001 T1136.002 T1136.003 T1205.001 T1505.002 T1505.003 T1505.004 T1505.005 T1542.001 T1542.003 T1542.004 T1542.005 T1543.001 T1543.002 T1543.003 T1543.004 T1543.005 T1546.003 T1546.004 T1546.013 T1547.003 T1547.004 T1547.006 T1547.007 T1547.009 T1547.012 T1547.013 T1556.001 T1556.003 T1556.004 T1556.006 T1556.007 T1556.008 T1556.009 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.012 T1574.014

Privilege Escalation

T1037 T1053 T1055 T1078 T1098 T1134 T1484 T1543 T1546 T1548 T1574 T1611 T1037.002 T1037.003 T1037.004 T1037.005 T1053.002 T1053.003 T1053.005 T1053.006 T1053.007 T1055.008 T1055.009 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.004 T1098.005 T1098.006 T1098.007 T1134.001 T1134.002 T1134.003 T1134.005 T1543.001 T1543.002 T1543.003 T1543.004 T1543.005 T1546.003 T1546.004 T1546.013 T1547.003 T1547.004 T1547.006 T1547.007 T1547.009 T1547.012 T1547.013 T1548.002 T1548.003 T1548.005 T1548.006 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.012 T1574.014

Defense Evasion

T1027 T1036 T1055 T1070 T1078 T1134 T1197 T1205 T1218 T1222 T1484 T1542 T1548 T1550 T1553 T1556 T1562 T1574 T1578 T1599 T1601 T1610 T1612 T1622 T1647 T1036.003 T1036.005 T1036.010 T1055.008 T1055.009 T1070.001 T1070.002 T1070.003 T1070.007 T1070.008 T1070.009 T1078.002 T1078.003 T1078.004 T1134.001 T1134.002 T1134.003 T1134.005 T1205.001 T1218.002 T1218.007 T1218.012 T1222.001 T1222.002 T1542.001 T1542.003 T1542.004 T1542.005 T1548.002 T1548.003 T1548.005 T1548.006 T1550.002 T1550.003 T1553.003 T1556.001 T1556.003 T1556.004 T1556.006 T1556.007 T1556.008 T1556.009 T1562.001 T1562.002 T1562.004 T1562.006 T1562.007 T1562.008 T1562.009 T1562.012 T1564.004 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.012 T1574.014 T1578.001 T1578.002 T1578.003 T1578.005 T1599.001 T1601.001 T1601.002

Credential Access

Compliance Mappings

ISO 27001:2022

A.5.15A.5.33A.8.3A.8.4A.8.18A.8.20A.8.26

ISO 27002:2022

5.158.38.4

COBIT 2019

DSS05DSS06

CIS Controls v8

CIS 3.3CIS 6CIS 6.7CIS 6.8CIS 13.9

NIST CSF 2.0

PR.AA-05PR.DS-01PR.DS-10PR.IR-01

SOC 2 TSC

CC6.1CC6.6CC6.6-POF2

PCI DSS v4.0.1

1.2.83.47.27.3

CSA CCM v4

DSP-17IAM-16

CSA AICM v1

DSP-17IAM-16MDS-07

FINOS CCC

CCC-C05CCC-C11

ISO 42001:2023

A.9.2A.9.4

IEC 62443

3-3 SR 2.13-3 SR 4.1

NIS2 Directive

Art. 21(2)(i)

MAS TRM

915

APRA CPS 234

Para 22-23

ASD Essential Eight

E8-8 ML3

BSI IT-Grundschutz

ORP.4SYS.1.1SYS.2.1

ANSSI

Hygiene.14Hygiene.15Hygiene.17SecNumCloud.10.3

FINMA Circular 2023/1

IV.B.d(59)IV.B.d(60)IV.C(61)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)Art.25(2)Art.32(1)(b)

EU DORA

Art.9(4)(c)

BIO2

5.158.38.4

RBI CSF

Annex1.8ITGRCA.19

FISC Security Guidelines

FISC.T2FISC.T5FISC.T11

LGPD + BCB 4893

BCB.Art.3BCB.OpenFinanceBCB.PIXLGPD.Art.11LGPD.Art.46

HKMA TM-E-1

TME1.8.1TME1.10.3TME1.11.2

MLPS 2.0

8.1.3.28.1.4.28.28.48.5

DNB Good Practice

DNB.12.3DNB.17.2DNB.20.1

EU CRA

CRA.I.2d

SWIFT CSCF

SWIFT.2.9SWIFT.2.11ASWIFT.5.1SWIFT.5.4SWIFT.6.3

SAMA CSF

3.1

NCA ECC

2-22-7

UAE IA

T9

CBB TM

TM-6

Qatar NIA

AC

CBUAE

CR-4

CBE CSF

CTO-1CTO-5

SA JS2

JS2-7.1

CBN CSF

Part3.2Part5.2

BoG CISD

CISD-IXCISD-VIII

POPIA

s19

BoM CTRM

3.3

IOSCO Cyber Resilience

PROT-1

BCBS 239

Principle 11

CPMI-IOSCO PFMI

CG.PRPFMI.P17

FFIEC IS

II.C.7(b)II.C.13(a)II.C.15II.C.15(a)II.C.15(b)II.C.18

NYDFS 500

500.7

HIPAA Security Rule

§164.308(a)(3)(i)§164.308(a)(3)(ii)(A)§164.308(a)(4)(i)§164.308(a)(4)(ii)(B)§164.308(a)(4)(ii)(C)§164.312(a)(1)§164.314(b)(2)

ECB CROE

CROE.2.3.1

EBA ICT Guidelines

3.4.2

SEBI CSCRF

PR.AA

BOT Cyber Resilience

Ch2.2

CMMC 2.0

AC

NERC CIP

CIP-007-6CIP-011-3

10 CFR 73.54

73.54(c)(1)RG5.71-A-AC

TSA Pipeline SD

SD-2 Sec B

IEEE 1686-2022

5.15.9

DOE C2M2 v2.1

ACCESS

API 1164

Sec 6

AWIA

AWWA Sec 3

IAEA NSS 17-T

Sec 5.3

CBEST

CBEST.9

TIBER-EU

TIBER.CONF

PCI HSM

48

Common Criteria

CC Part 2 — FDP

ISAE 3402

Clause 4

Solvency II

DR.266-DataSecEIOPA-ICT-4.4

Lloyd's Minimum Standards

MS1.1MS2.1MS5.1MS6.1MS8.3

NAIC Insurance Data Security

4-access4B

PRA SS1/23

P3.3P3.6P-IT.1

FCA SYSC 13

SYSC 13.7.3

HITRUST CSF v11

01.a01.c13.e

FDA 21 CFR Part 11

§11.10(d)§11.10(g)

FDA Cybersecurity Guidance

SA-1SA-4

ISO 27799

9.19.5H.4

NHS DSPT

NDG-1.1NDG-4.1

OWASP MASVS v2.1

MASVS-AUTH-1MASVS-AUTH-3MASVS-PLATFORM-1MASVS-PRIVACY-1MASVS-PRIVACY-4MASVS-STORAGE-1

CCSS v9.0

1.03.51.05.1

MiCA

Art.40(1)Art.55(1)Art.62(9)Art.63(1)Art.67(1)Art.97(1)

Basel SCO60

SCO60.61SCO60.62SCO60.66

BSSC Standards

GSP-11KMS-06KMS-09NOS-05TIS-07

SEC Custody (Digital Assets)

SEC-CD-02SEC-CD-05

India DPDPA

Act.8(5)Act.11Rules.6(1)(b)Rules.Sch1.B.3-4Rules.Sch1.B.7Rules.Sch2

ISO 17799 (legacy)

11.2.411.4.5

COBIT 4.1 (legacy)

PO2.3AI2.4DS11.6