<?xml version="1.0"?>

<rss version="2.0">


<channel>
<title>Home - All Categories - FedRAMP  - Access Control &amp;#40;AC&amp;#41;  </title>
<link>http://www.compliancewiki.org/category/fedramp/access-control-ac/8/</link>
<description>This RSS Feed contains Articles of Category in the knowledge base. You can click on the title to view its content. Powered by PHPKB (https://www.phpkb.com)</description>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-separation-of-duties-ac-5-23.html</guid>
										<title>FedRAMP Separation of Duties AC-5</title>
										<link>http://www.compliancewiki.org/article/fedramp-separation-of-duties-ac-5-23.html</link>
										<description><![CDATA[Overview:The organization:a. Separates [Assignment: organization-defined duties of individuals];b. Documents separation of duties of individuals; andc. Defines information system access authorizations to support separation of duties. Supplemental...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-account-management-ac-2-10.html</guid>
										<title>FedRAMP Account Management AC-2</title>
										<link>http://www.compliancewiki.org/article/fedramp-account-management-ac-2-10.html</link>
										<description><![CDATA[Overview:The organization:a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: [Assignment: organization-defined information system account types];b. Assigns account...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-least-privilege-ac-6-24.html</guid>
										<title>FedRAMP Least Privilege AC-6</title>
										<link>http://www.compliancewiki.org/article/fedramp-least-privilege-ac-6-24.html</link>
										<description><![CDATA[Overview:The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-session-lock-ac-11-33.html</guid>
										<title>FedRAMP Session Lock AC-11</title>
										<link>http://www.compliancewiki.org/article/fedramp-session-lock-ac-11-33.html</link>
										<description><![CDATA[Overview:The information system:a. Prevents further access to the system by initiating a session lock after [Assignment: organization-defined time period] of inactivity or upon receiving a request from a user; andb. Retains the session lock until the...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-session-termination-ac-12-35.html</guid>
										<title>FedRAMP Session Termination AC-12</title>
										<link>http://www.compliancewiki.org/article/fedramp-session-termination-ac-12-35.html</link>
										<description><![CDATA[Overview:The information system automatically terminates a user session after [Assignment: organization-defined conditions or trigger events requiring session disconnect]. Supplemental Guidance:This control addresses the termination of user-initiated...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-disable-inactive-accounts-ac-2-3-13.html</guid>
										<title>FedRAMP Disable Inactive Accounts AC-2 &#40;3&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-disable-inactive-accounts-ac-2-3-13.html</link>
										<description><![CDATA[Overview:The information system automatically disables inactive accounts after [Assignment: organization-defined time period]. Action Items:1) Disable inactive accounts on a predefined basis Related Documents:1) Access Control Policy 2) Identity and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-account-monitoring-atypical-usage-ac-2-12-19.html</guid>
										<title>FedRAMP Account Monitoring / Atypical Usage AC-2 &#40;12&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-account-monitoring-atypical-usage-ac-2-12-19.html</link>
										<description><![CDATA[Overview:The organization:(a) Monitors information system accounts for [Assignment: organization-defined atypical use]; and(b) Reports atypical usage of information system accounts to [Assignment: organization-defined personnel or roles]....]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-access-control-policy-and-procedures-ac-1-9.html</guid>
										<title>FedRAMP Access Control Policy and Procedures AC-1</title>
										<link>http://www.compliancewiki.org/article/fedramp-access-control-policy-and-procedures-ac-1-9.html</link>
										<description><![CDATA[Overview:The organization:a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-automated-system-account-management-ac-2-1-11.html</guid>
										<title>FedRAMP Automated System Account Management AC-2 &#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-automated-system-account-management-ac-2-1-11.html</link>
										<description><![CDATA[Overview:The organization employs automated mechanisms to support the management of information system accounts. Supplemental Guidance:The use of automated mechanisms can include, for example: using email or text messaging to automatically notify...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-prohibit-non-privileged-users-from-executing-privileged-functions-ac-6-10-29.html</guid>
										<title>FedRAMP Prohibit Non-Privileged Users From Executing Privileged Functions AC-6 &#40;10&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-prohibit-non-privileged-users-from-executing-privileged-functions-ac-6-10-29.html</link>
										<description><![CDATA[Overview:The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures. Supplemental Guidance:Privileged functions include,...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-use-of-external-information-systems-ac-20-47.html</guid>
										<title>FedRAMP Use of External Information Systems AC-20</title>
										<link>http://www.compliancewiki.org/article/fedramp-use-of-external-information-systems-ac-20-47.html</link>
										<description><![CDATA[Overview:The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:a. Access...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-inactivity-logout-ac-2-5-15.html</guid>
										<title>FedRAMP Inactivity Logout AC-2 &#40;5&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-inactivity-logout-ac-2-5-15.html</link>
										<description><![CDATA[Overview:The organization requires that users log out when [Assignment: organization-defined time-period of expected inactivity or description of when to log out] Related control: SC-23 Action Items:1) Enable logouts due to a specific period of...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-privileged-accounts-ac-6-5-27.html</guid>
										<title>FedRAMP Privileged Accounts AC-6 &#40;5&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-privileged-accounts-ac-6-5-27.html</link>
										<description><![CDATA[Overview:The organization restricts privileged accounts on the information system to [Assignment: organization-defined personnel or roles]. Supplemental Guidance:Privileged accounts, including super user accounts, are typically described as system...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-role-based-schemes-ac-2-7-16.html</guid>
										<title>FedRAMP Role-based Schemes AC-2 &#40;7&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-role-based-schemes-ac-2-7-16.html</link>
										<description><![CDATA[Overview:The organization:(a) Establishes and administers privileged user accounts in accordance with a role-based access scheme that organizes allowed information system access and privileges into roles;(b) Monitors privileged role assignments; and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-publicly-accessible-content-ac-22-51.html</guid>
										<title>FedRAMP Publicly Accessible Content AC-22</title>
										<link>http://www.compliancewiki.org/article/fedramp-publicly-accessible-content-ac-22-51.html</link>
										<description><![CDATA[Overview:The organization:a. Designates individuals authorized to post information onto a publicly accessible information system;b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;c....]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-removal-of-temporary-emergency-accounts-ac-2-2-12.html</guid>
										<title>FedRAMP Removal of Temporary / Emergency Accounts AC-2 &#40;2&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-removal-of-temporary-emergency-accounts-ac-2-2-12.html</link>
										<description><![CDATA[Overview:The information system automatically [Selection: removes; disables] temporary and emergency accounts after [Assignment: organization-defined time period for each type of account]. Supplemental Guidance:This control enhancement requires the...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-restrictions-on-use-of-shared-groups-accounts-ac-2-9-17.html</guid>
										<title>FedRAMP Restrictions on Use of Shared Groups / Accounts AC-2 &#40;9&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-restrictions-on-use-of-shared-groups-accounts-ac-2-9-17.html</link>
										<description><![CDATA[Overview:The organization only permits the use of shared/group accounts that meet [Assignment: organization-defined conditions for establishing shared/group accounts]. Action Items:1) Define conditions for use of shared/group accounts if utilized...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-authentication-and-encryption-ac-18-1-44.html</guid>
										<title>FedRAMP Authentication and Encryption AC-18 &#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-authentication-and-encryption-ac-18-1-44.html</link>
										<description><![CDATA[Overview:The information system protects wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption. Related Controls:&gt;/b&gt; SC-8, SC-13. Â  Action Items:1) Ensure encryption requirements exists...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-auditing-the-use-of-privileged-functions-ac-6-9-28.html</guid>
										<title>FedRAMP Auditing the Use of Privileged Functions AC-6 &#40;9&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-auditing-the-use-of-privileged-functions-ac-6-9-28.html</link>
										<description><![CDATA[Overview:The information system audits the execution of privileged functions. Supplemental Guidance:Misuse of privileged functions, either intentionally or unintentionally by authorized users, or by unauthorized external entities that have...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-protection-of-confidentiality-integrity-using-encryption-ac-17-2-39.html</guid>
										<title>FedRAMP Protection of Confidentiality / Integrity Using Encryption AC-17 &#40;2&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-protection-of-confidentiality-integrity-using-encryption-ac-17-2-39.html</link>
										<description><![CDATA[Overview:The information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions. Supplemental Guidance:The encryption strength of mechanism is selected based on the security categorization of...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-system-use-notification-ac-8-31.html</guid>
										<title>FedRAMP System Use Notification AC-8</title>
										<link>http://www.compliancewiki.org/article/fedramp-system-use-notification-ac-8-31.html</link>
										<description><![CDATA[Overview:The information system:a. Displays to users [Assignment: organization-defined system use notification message or banner] before granting access to the system that provides privacy and security notices consistent with applicable federal laws,...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-disconnect-disable-access-ac-17-9-42.html</guid>
										<title>FedRAMP Disconnect / Disable Access AC-17 &#40;9&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-disconnect-disable-access-ac-17-9-42.html</link>
										<description><![CDATA[Overview:The organization provides the capability to expeditiously disconnect or disable remote access to the information system within [Assignment: organization-defined time period]. Supplemental Guidance:This control enhancement requires...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-automated-audit-actions-ac-2-4-14.html</guid>
										<title>FedRAMP Automated Audit Actions AC-2 &#40;4&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-automated-audit-actions-ac-2-4-14.html</link>
										<description><![CDATA[Overview:The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies [Assignment: organization-defined personnel or roles]. Related controls: AU-2, AU-12 Action Items:1) Enable...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-automated-monitoring-control-ac-17-1-38.html</guid>
										<title>FedRAMP Automated Monitoring / Control AC-17 &#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-automated-monitoring-control-ac-17-1-38.html</link>
										<description><![CDATA[Overview:The information system monitors and controls remote access methods. Supplemental Guidance:Automated monitoring and control of remote access sessions allows organizations to detect cyber attacks and also ensure ongoing compliance with remote...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-access-control-for-mobile-devices-ac-19-45.html</guid>
										<title>FedRAMP Access Control for Mobile Devices AC-19</title>
										<link>http://www.compliancewiki.org/article/fedramp-access-control-for-mobile-devices-ac-19-45.html</link>
										<description><![CDATA[Overview:The organization:a. Establishes usage restrictions, configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices; andb. Authorizes the connection of mobile devices to...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-remote-access-ac-17-37.html</guid>
										<title>FedRAMP Remote Access AC-17</title>
										<link>http://www.compliancewiki.org/article/fedramp-remote-access-ac-17-37.html</link>
										<description><![CDATA[Overview:The organization:a. Establishes and documents usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; andb. Authorizes remote access to the information system prior to...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-physical-and-logical-separation-of-information-flows-ac-4-21-22.html</guid>
										<title>FedRAMP Physical and Logical Separation of Information Flows AC-4 &#40;21&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-physical-and-logical-separation-of-information-flows-ac-4-21-22.html</link>
										<description><![CDATA[Overview:The information system separates information flows logically or physically using [Assignment: organization-defined mechanisms and/or techniques] to accomplish [Assignment: organization- defined required separations by types of information]....]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-concurrent-session-control-ac-10-32.html</guid>
										<title>FedRAMP Concurrent Session Control AC-10</title>
										<link>http://www.compliancewiki.org/article/fedramp-concurrent-session-control-ac-10-32.html</link>
										<description><![CDATA[Overview:The information system limits the number of concurrent sessions for each [Assignment: organization-defined account and/or account type] to [Assignment: organization-defined number]. Supplemental Guidance:Organizations may define the maximum...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-pattern-hiding-displays-ac-11-1-34.html</guid>
										<title>FedRAMP Pattern Hiding Displays AC-11 &#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-pattern-hiding-displays-ac-11-1-34.html</link>
										<description><![CDATA[Overview:The information system conceals, via the session lock, information previously visible on the display with a publicly viewable image. Supplemental Guidance:Publicly viewable images can include static or dynamic images, for example, patterns...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-privileged-commands-access-ac-17-4-41.html</guid>
										<title>FedRAMP Privileged Commands / Access AC-17 &#40;4&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-privileged-commands-access-ac-17-4-41.html</link>
										<description><![CDATA[Overview:The organization:(a) Authorizes the execution of privileged commands and access to security-relevant information via remote access only for [Assignment: organization-defined needs]; and(b) Documents the rationale for such access in the...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-unsuccessful-logon-attempts-ac-7-30.html</guid>
										<title>FedRAMP Unsuccessful Logon Attempts AC-7</title>
										<link>http://www.compliancewiki.org/article/fedramp-unsuccessful-logon-attempts-ac-7-30.html</link>
										<description><![CDATA[Overview:The information system:a. Enforces a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]; andb. Automatically [Selection: locks the account...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-non-privileged-access-for-non-security-functions-ac-6-2-26.html</guid>
										<title>FedRAMP Non-privileged Access for Non-security Functions AC-6 &#40;2&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-non-privileged-access-for-non-security-functions-ac-6-2-26.html</link>
										<description><![CDATA[Overview:The organization requires that users of information system accounts, or roles, with access to [Assignment: organization-defined security functions or security-relevant information], use non- privileged accounts or roles, when accessing...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-full-device-container-based-encryption-ac-19-5-46.html</guid>
										<title>FedRAMP Full Device / Container-based Encryption AC-19 &#40;5&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-full-device-container-based-encryption-ac-19-5-46.html</link>
										<description><![CDATA[Overview:The organization employs [Selection: full-device encryption; container encryption] to protect the confidentiality and integrity of information on [Assignment: organization-defined mobile devices]. Supplemental Guidance:Container-based...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-wireless-access-ac-18-43.html</guid>
										<title>FedRAMP Wireless Access AC-18</title>
										<link>http://www.compliancewiki.org/article/fedramp-wireless-access-ac-18-43.html</link>
										<description><![CDATA[Overview:The organization:a. Establishes usage restrictions, configuration/connection requirements, and implementation guidance for wireless access; andb. Authorizes wireless access to the information system prior to allowing such connections....]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-information-sharing-ac-21-50.html</guid>
										<title>FedRAMP Information Sharing AC-21</title>
										<link>http://www.compliancewiki.org/article/fedramp-information-sharing-ac-21-50.html</link>
										<description><![CDATA[Overview:The organization:a. Facilitates information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for [Assignment: organization...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-permitted-actions-without-identification-or-authentication-ac-14-36.html</guid>
										<title>FedRAMP Permitted Actions Without Identification or Authentication AC-14</title>
										<link>http://www.compliancewiki.org/article/fedramp-permitted-actions-without-identification-or-authentication-ac-14-36.html</link>
										<description><![CDATA[Overview:The organization:a. Identifies [Assignment: organization-defined user actions] that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; andb....]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-group-accounts-credential-termination-ac-2-10-18.html</guid>
										<title>FedRAMP Group Accounts Credential Termination AC-2 &#40;10&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-group-accounts-credential-termination-ac-2-10-18.html</link>
										<description><![CDATA[Overview:The information system terminates shared/group account credentials when members leave the group. Action Items:1) Terminate shared account credentials when members leave the group Related Documents:1) Access Control Policy 2) Identity and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-authorize-access-to-security-functions-ac-6-1-25.html</guid>
										<title>FedRAMP Authorize Access to Security Functions AC-6 &#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-authorize-access-to-security-functions-ac-6-1-25.html</link>
										<description><![CDATA[Overview:The organization explicitly authorizes access to [Assignment: organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information]. Supplemental Guidance:Security functions include, for...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-information-flow-enforcement-ac-4-21.html</guid>
										<title>FedRAMP Information Flow Enforcement AC-4</title>
										<link>http://www.compliancewiki.org/article/fedramp-information-flow-enforcement-ac-4-21.html</link>
										<description><![CDATA[Overview:The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on [Assignment: organization-defined information flow control policies]. Supplemental...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-portable-storage-devices-ac-20-2-49.html</guid>
										<title>FedRAMP Portable Storage Devices AC-20 &#40;2&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-portable-storage-devices-ac-20-2-49.html</link>
										<description><![CDATA[Overview:The organization [Selection: restricts; prohibits] the use of organization-controlled portable storage devices by authorized individuals on external information systems. Supplemental Guidance:Limits on the use of organization-controlled...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-access-enforcement-ac-3-20.html</guid>
										<title>FedRAMP Access Enforcement AC-3</title>
										<link>http://www.compliancewiki.org/article/fedramp-access-enforcement-ac-3-20.html</link>
										<description><![CDATA[Overview:The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. Supplemental Guidance:Access control policies (e.g., identity-based...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-managed-access-control-points-ac-17-3-40.html</guid>
										<title>FedRAMP Managed Access Control Points AC-17 &#40;3&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-managed-access-control-points-ac-17-3-40.html</link>
										<description><![CDATA[Overview:The information system routes all remote accesses through [Assignment: organization-defined number] managed network access control points. Supplemental Guidance:Limiting the number of access control points for remote accesses reduces the...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-limits-on-authorized-use-ac-20-1-48.html</guid>
										<title>FedRAMP Limits on Authorized Use AC-20 &#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-limits-on-authorized-use-ac-20-1-48.html</link>
										<description><![CDATA[Overview:The organization permits authorized individuals to use an external information system to access the information system or to process, store, or transmit organization-controlled information only when the organization:(a) Verifies the...]]></description>

									</item>

</channel>

</rss>