NIST SP 800-53 Rev. 5
AC-3(4)
Access Control
enhancement

Discretionary Access Control

Parent: AC-3

Description

Enforce [organization-defined parameter] over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information can do one or more of the following: a. Pass the information to any other subjects or objects; b. Grant its privileges to other subjects; c. Change security attributes on subjects, objects, the system, or the system’s components; d. Choose the security attributes to be associated with newly created or revised objects; or e. Change the rules governing access control.

Mapped SPARTA techniques

75 techniques

Cite as SafeMode Space, nist-80053-rev5 AC-3(4).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.