AC-9(3): Notification of Account Changes

Control Family:

Access Control

Threats Addressed:


(Not part of any baseline)

Previous Version:

Control Statement

Notify the user, upon successful logon, of changes to [Assignment: organization-defined security-related characteristics or parameters of the user’s account] during [Assignment: organization-defined time period].

Supplemental Guidance

Information about changes to security-related account characteristics within a specified time period allows users to recognize if changes were made without their knowledge.