|
controlAC-24

Access Control Decisions (AC-24)

[organization-defined] to ensure [organization-defined] are applied to each access request prior to access enforcement.

access-controlauthorizationleast-privilege

Why These Connect

Maps To3

These are equivalent or closely aligned requirements in other frameworks.

Supports4

These related controls work together — a change to one may affect the others.

Enhances2

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(3)

PR.AA-05PR.AA-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.AA-05PR.AA-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(2)

SelectionSelection (one-or-more): establish procedures / implement mechanisms
Assignmentorganization-defined access control decisions

Control Enhancements(2)