AC-03 Access Enforcement
Access Control
Description
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
Supplemental Guidance
Access control policies control access between active entities or subjects (i.e., users or processes acting on behalf of users) and passive entities or objects (i.e., devices, files, records, domains) in organizational systems. In addition to enforcing authorized access at the system level and recognizing that systems can host many applications and services in support of mission and business functions, access enforcement mechanisms can also be employed at the application and service level to provide increased information security and privacy. In contrast to logical access controls that are implemented within the system, physical access controls are addressed by the controls in the Physical and Environmental Protection (PE) family.
Enhancements (13)
What NIST adds to this control. Select one to read its statement.
AC-03(02) Dual Authorization
Enforce dual authorization for [Assignment: organization-defined privileged commands and/or other organization-defined actions].
AC-03(03) Mandatory Access Control
Enforce [Assignment: organization-defined mandatory access control policy] over the set of covered subjects and objects specified in the policy, and where the policy: a. Is uniformly enforced across the covered subjects and objects within the system; b. Specifies that a subject that has been granted access to information is constrained from doing any of the following; 1. Passing the information to unauthorized subjects or objects; 2. Granting its privileges to other subjects; 3. Changing one or more security attributes (specified by the policy) on subjects, objects, the system, or system components; 4. Choosing the security attributes and attribute values (specified by the policy) to be associated with newly created or modified objects; and 5. Changing the rules governing access control; and c. Specifies that [Assignment: organization-defined subjects] may explicitly be granted [Assignment: organization-defined privileges] such that they are not limited by any defined subset (or all) of the above constraints.
AC-03(04) Discretionary Access Control
Enforce [Assignment: organization-defined discretionary access control policy] over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information can do one or more of the following: a. Pass the information to any other subjects or objects; b. Grant its privileges to other subjects; c. Change security attributes on subjects, objects, the system, or the system’s components; d. Choose the security attributes to be associated with newly created or revised objects; or e. Change the rules governing access control.
AC-03(05) Security-relevant Information
Prevent access to [Assignment: organization-defined security-relevant information] except during secure, non-operable system states.
AC-03(07) Role-based Access Control
Enforce a role-based access control policy over defined subjects and objects and control access based upon [Assignment: organization-defined roles and users authorized to assume such roles].
AC-03(08) Revocation of Access Authorizations
Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on [Assignment: organization-defined rules governing the timing of revocations of access authorizations].
AC-03(09) Controlled Release
Release information outside of the system only if: a. The receiving [Assignment: organization-defined system or system component] provides [Assignment: organization-defined controls]; and b. [Assignment: organization-defined controls] are used to validate the appropriateness of the information designated for release.
AC-03(10) Audited Override of Access Control Mechanisms
Employ an audited override of automated access control mechanisms under [Assignment: organization-defined conditions] by [Assignment: organization-defined roles].
AC-03(11) Restrict Access to Specific Information Types
Restrict access to data repositories containing [Assignment: organization-defined information types].
AC-03(12) Assert and Enforce Application Access
a. Require applications to assert, as part of the installation process, the access needed to the following system applications and functions: [Assignment: organization-defined system applications and functions]; b. Provide an enforcement mechanism to prevent unauthorized access; and c. Approve access changes after initial installation of the application.
AC-03(13) Attribute-based Access Control
Enforce attribute-based access control policy over defined subjects and objects and control access based upon [Assignment: organization-defined attributes to assume access permissions].
AC-03(14) Individual Access Privacy
Provide [Assignment: organization-defined mechanisms] to enable individuals to have access to the following elements of their personally identifiable information: [Assignment: organization-defined elements].
AC-03(15) Discretionary and Mandatory Access Control
a. Enforce [Assignment: organization-defined mandatory access control policy] over the set of covered subjects and objects specified in the policy; and b. Enforce [Assignment: organization-defined discretionary access control policy] over the set of covered subjects and objects specified in the policy.
Patterns that use this control (27)
Grouped by the emphasis each pattern gives it.
Critical (19)
- SP-001 Client Module
- SP-002 Server Module
- SP-004 SOA Publication and Location Pattern
- SP-005 SOA Internal Service Usage Pattern
- SP-008 Public Web Server Pattern
- SP-011 Cloud Computing Pattern
- SP-013 Data Security Pattern
- SP-022 Board of Directors Room
- SP-023 Industrial Control Systems
- SP-027 Secure LLM Usage
- SP-028 Secure DevOps Pipeline Pattern
- SP-029 Zero Trust Architecture
- SP-030 API Security
- SP-032 Modern Authentication
- SP-044 SaaS Identity Lifecycle Management
- SP-047 Secure Agentic AI Frameworks
- SP-051 Tokenised Asset Security Architecture (draft)
- SP-053 Zero-Knowledge Proof Architecture (draft)
- SP-054 CBDC and Digital Currency Infrastructure (draft)
Important (6)
MITRE ATT&CK Techniques (281)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.