|
controlAC-11

Device Lock (AC-11)

Prevent further access to the system by [organization-defined] ; and Retain the device lock until the user reestablishes access using established identification and authentication procedures.

Security Baselines

MODERATEHIGHLOW
access-controlauthorizationleast-privilege

Why These Connect

Maps To2

These are equivalent or closely aligned requirements in other frameworks.

Baselined In2

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports6

These related controls work together — a change to one may affect the others.

Enhances1

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(2)

ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5

Organization-Defined Parameters(2)

SelectionSelection (one-or-more): initiating a device lock after {{ insert: param, ac-11_odp.02 }} of inactivity / requiring the user to initiate a device lock before leaving the system unattended
Assignmentorganization-defined time period

Control Enhancements(1)