NIST SP 800-53 Rev. 5
AC-2
Access Control

Account Management

Description

a. Define and document the types of accounts allowed and specifically prohibited for use within the system; b. Assign account managers; c. Require [organization-defined parameter] for group and role membership; d. Specify: e. Require approvals by [organization-defined parameter] for requests to create accounts; f. Create, enable, modify, disable, and remove accounts in accordance with [organization-defined parameter]; g. Monitor the use of accounts; h. Notify account managers and [organization-defined parameter] within: i. Authorize access to the system based on: j. Review accounts for compliance with account management requirements [organization-defined parameter]; k. Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and l. Align account management processes with personnel termination and transfer processes.

Mapped SPARTA techniques

97 techniques

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Cite as SafeMode Space, nist-80053-rev5 AC-2.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.