AC: Access Control

OT Tailoring Considerations

Before implementing controls in the AC family, consider the trade-offs among security, privacy, latency, performance, throughput, and reliability. For example, the organization considers whether latency induced from the use of confidentiality and integrity mechanisms that employ cryptographic mechanisms would adversely impact the operational performance of the OT.

When the OT cannot support the specific access control requirements of a control, the organization employs compensating controls in accordance with the general tailoring guidance. Examples of compensating controls are given with each control as appropriate.

Controls

AC-1: Policy and Procedures

Baseline(s):

  • Low
  • Moderate
  • High
  • Privacy
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] access control policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the implementation…

AC-2: Account Management

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Define and document the types of accounts allowed and specifically prohibited for use within the system; Assign account managers; Require [Assignment: organization-defined prerequisites and criteria] for group and role membership; Specify: Authorized users of the system; Group and role membership; and Access authorizations (i.e., privileges) and [Assignment: organization-defined attributes (as required)] for each account; Require…

AC-3: Access Enforcement

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

AC-4: Information Flow Enforcement

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [Assignment: organization-defined information flow control policies].

AC-5: Separation of Duties

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Identify and document [Assignment: organization-defined duties of individuals] ; and Define system access authorizations to support separation of duties.

AC-6: Least Privilege

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.

AC-7: Unsuccessful Logon Attempts

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period] ; and Automatically [Assignment (one or more): lock the account or node for [Assignment: organization-defined time period] , lock the account or node until released by an administrator, delay next logon prompt per [Assignment: organization-defined…

AC-8: System Use Notification

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Display [Assignment: organization-defined system use notification] to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and state that: Users are accessing a U.S. Government system; System usage may be monitored, recorded, and subject to audit; Unauthorized use of…

AC-10: Concurrent Session Control

Baseline(s):

  • High
  • OT High (SP 800-82r3)

Limit the number of concurrent sessions for each [Assignment: organization-defined account and/or account types] to [Assignment: organization-defined number].

AC-11: Device Lock

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Prevent further access to the system by [Assignment (one or more): initiating a device lock after [Assignment: organization-defined time period] of inactivity, requiring the user to initiate a device lock before leaving the system unattended] ; and Retain the device lock until the user reestablishes access using established identification and authentication procedures.

AC-12: Session Termination

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Automatically terminate a user session after [Assignment: organization-defined conditions or trigger events].

AC-14: Permitted Actions Without Identification or Authentication

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Identify [Assignment: organization-defined user actions] that can be performed on the system without identification or authentication consistent with organizational mission and business functions; and Document and provide supporting rationale in the security plan for the system, user actions not requiring identification or authentication.

AC-16: Security and Privacy Attributes

Baseline(s):

(Not part of any baseline)

Provide the means to associate [Assignment: organization-defined types of security and privacy attributes] with [Assignment: organization-defined security and privacy attribute values] for information in storage, in process, and/or in transmission; Ensure that the attribute associations are made and retained with the information; Establish the following permitted security and privacy attributes from the attributes defined in…

AC-17: Remote Access

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and Authorize each type of remote access to the system prior to allowing such connections.

AC-18: Wireless Access

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access; and Authorize each type of wireless access to the system prior to allowing such connections.

AC-19: Access Control for Mobile Devices

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and Authorize the connection of mobile devices to organizational systems.

AC-20: Use of External Systems

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

[Assignment (one or more): establish [Assignment: organization-defined terms and conditions] , identify [Assignment: organization-defined controls asserted] ] , consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to: Access the system from external systems; and Process, store, or transmit organization-controlled information using external systems; or Prohibit…

AC-21: Information Sharing

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information’s access and use restrictions for [Assignment: organization-defined information-sharing circumstances] ; and Employ [Assignment: organization-defined automated mechanisms] to assist users in making information sharing and collaboration decisions.

AC-22: Publicly Accessible Content

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Designate individuals authorized to make information publicly accessible; Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information; Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included; and Review the content on the publicly accessible system for nonpublic…

AC-23: Data Mining Protection

Baseline(s):

(Not part of any baseline)

Employ [Assignment: organization-defined techniques] for [Assignment: organization-defined data storage objects] to detect and protect against unauthorized data mining.

AC-24: Access Control Decisions

Baseline(s):

(Not part of any baseline)

[Assignment (one or more): establish procedures, implement mechanisms] to ensure [Assignment: organization-defined access control decisions] are applied to each access request prior to access enforcement.

AC-25: Reference Monitor

Baseline(s):

(Not part of any baseline)

Implement a reference monitor for [Assignment: organization-defined access control policies] that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured.