|
controlAC-14

Permitted Actions Without Identification or Authentication (AC-14)

Identify [organization-defined] that can be performed on the system without identification or authentication consistent with organizational mission and business functions; and Document and provide supporting rationale in the security plan for the system, user actions not requiring identification or authentication.

Security Baselines

LOWMODERATEHIGH
access-controlauthorizationleast-privilege

Why These Connect

Maps To2

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports6

These related controls work together — a change to one may affect the others.

Enhances1

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(2)

PR.AA-01PR.AA-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.AA-01PR.AA-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Control Enhancements(1)