|
controlAC-5
Separation of Duties (AC-5)
Identify and document [organization-defined] ; and Define system access authorizations to support separation of duties.
Security Baselines
MODERATEHIGHLOW
access-controlauthorizationleast-privilege
Why These Connect
Maps To4
These are equivalent or closely aligned requirements in other frameworks.
Baselined In2
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports20
These related controls work together — a change to one may affect the others.
Mitigates3
This control helps defend against or reduce the risk of the linked threat technique.
Related Controls(17)
AC-2Account Management (AC-2)
LMH
AC-3Access Enforcement (AC-3)LMH
AC-6Least Privilege (AC-6)MH
AU-9Protection of Audit Information (AU-9)LMH
CM-5Access Restrictions for Change (CM-5)LMH
CM-11User-installed Software (CM-11)LMH
CP-9System Backup (CP-9)LMH
IA-2Identification and Authentication (Organizational Users) (IA-2)LMH
IA-4Identifier Management (IA-4)LMH
IA-5Authenticator Management (IA-5)LMH
IA-12Identity Proofing (IA-12)MH
MA-3Maintenance Tools (MA-3)MH
MA-5Maintenance Personnel (MA-5)LMH
PS-2Position Risk Designation (PS-2)LMH
SA-8Security and Privacy Engineering Principles (SA-8)LMH
SA-17Developer Security and Privacy Architecture and Design (SA-17)H
AU-6Audit Record Review, Analysis, and Reporting (AU-6)LMH
Threat Coverage(3 ATT&CK techniques)
Cross-Framework Mappings(4)
PR.AA-05PR.AA-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule4 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
PR.AA-05PR.AA-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5