|
controlAC-16

Security and Privacy Attributes (AC-16)

Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission; Ensure that the attribute associations are made and retained with the information; Establish the following permitted security and privacy attributes from the attributes defined in [AC-16a](#ac-16_smt.a) for [organization-defined]: [organization-defined]; Determine the following permitted attribute values or ranges for each of the established attributes

access-controlauthorizationleast-privilege

Why These Connect

Maps To3

These are equivalent or closely aligned requirements in other frameworks.

Supports19

These related controls work together — a change to one may affect the others.

Enhances10

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(3)

PR.AA-05PR.AA-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
PR.AA-05PR.AA-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(11)

Assignmentorganization-defined types of security attributes
Assignmentorganization-defined types of privacy attributes
Assignmentorganization-defined security attribute values
Assignmentorganization-defined privacy attribute values
Assignmentorganization-defined systems
Assignmentorganization-defined systems
Assignmentorganization-defined security attributes
Assignmentorganization-defined privacy attributes
Assignmentorganization-defined attribute values or ranges
Assignmentorganization-defined frequency
Assignmentorganization-defined frequency

Control Enhancements(10)