AC-2(1): Automated System Account Management

Control Family:

Access Control

Threats Addressed:

Baselines:

  • Moderate
  • High

Next Version:

Control Statement

The organization employs automated mechanisms to support the management of information system accounts.

Supplemental Guidance

The use of automated mechanisms can include, for example: using email or text messaging to automatically notify account managers when users are terminated or transferred; using the information system to monitor account usage; and using telephonic notification to report atypical system account usage.