# AC-13 Supervision and Review — Access Control

NIST SP 800-53 control. Family: AC Access Control. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.
Withdrawn from SP 800-53 by NIST. Its content moved into AC-02, AU-06.

Statement: The organization supervises and reviews the activities of users with respect to the enforcement and usage of information system access controls.
Guidance: The organization reviews audit records (e.g., user activity logs) for inappropriate activities in accordance with organizational procedures. The organization investigates any unusual information system-related activities and periodically reviews changes to access authorizations. The organization reviews more frequently the activities of users with significant information system roles and responsibilities. The extent of the audit record reviews is based on the FIPS 199 impact level of the information system. For example, for low-impact systems, it is not intended that security logs be reviewed frequently for every workstation, but rather at central points such as a web proxy or email servers and when specific circumstances warrant review of other audit records. NIST Special Publication 800-92 provides guidance on computer security log management.

## Patterns that use it (1)
- Important (1): SP-011 Cloud Computing Pattern

## Clauses by framework (16 frameworks)
- cobit_2019: DSS05
- iso_42001_2023: A.6.2.6
- nis2: Art. 21(2)(i)
- mas_trm: 9
- bsi_grundschutz: ORP.4
- anssi: Hygiene.6, Hygiene.31, SecNumCloud.10.2
- osfi_b13: B-13.3.2, B-13.3.3
- finma_circular: IV.B.d(59), IV.B.d(60)
- gdpr: Art.5(1)(f), Art.5(2), Art.32(1)(d)
- fisc: FISC.T2
- hkma_tme1: TME1.8.1, TME1.8.2
- cbb_tm: TM-6
- qatar_nia: AC
- bot_cyber: Ch2.2
- cmmc_2: AC
- fca_sysc_13: SYSC 13.6.3

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AC-13
- Clauses only: /api/v1/controls/AC-13?fields=mappings
- Page for people: /controls/ac-13/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
