|
controlAC-5

Separation of Duties (AC-5)

Identify and document [organization-defined] ; and Define system access authorizations to support separation of duties.

Security Baselines

MODERATEHIGHLOW
access-controlauthorizationleast-privilege

Why These Connect

Maps To4

These are equivalent or closely aligned requirements in other frameworks.

Baselined In2

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports20

These related controls work together — a change to one may affect the others.

Mitigates3

This control helps defend against or reduce the risk of the linked threat technique.

Cross-Framework Mappings(4)

PR.AA-05PR.AA-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule4 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
PR.AA-05PR.AA-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5