NIST800-AC-3 AC-3 Access Enforcement
NIST800-AC-3 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
AC-3 Access Enforcement. Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC6.1 CC6.1 Logical access security over protected information assets (reviewed pair)
- SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) (closest match)
- SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials (closest match)
- SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties (closest match)
- SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal (closest match)
- SOC2-P5.1 P5.1 Data subject access (closest match)
- SOC2-PI1.4 PI1.4 Controls over output delivery (closest match)
HIPAA Security Rule
- 164.308(a)(3)(i) Workforce Security (Standard) (closest match)
- 164.308(a)(4)(i) Information Access Management (Standard) (closest match)
- 164.312(a)(1) Access Control (Standard) (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: AC - Access Control), in our words, not a statement of the standard and not binding on an assessor.
- the access-control policy and procedures
- the account-management and privilege records
- the periodic access-review output