San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

AC-2 Account Management

Access Control family. 93 Control Correlation Identifiers map to this control, and 37 STIG rules implement those CCIs.

1CAT I (high)
34CAT II (medium)
2CAT III (low)
93CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to AC-2
Red Hat Enterprise Linux 9V210
Microsoft Windows Server 2019V38
Microsoft Windows Server 2022V28
Microsoft Windows 10V34
Red Hat Enterprise Linux 8V23
KubernetesV22
Microsoft Windows 11V22

Control Correlation Identifiers mapped to AC-2

CCIDefinitionRev
CCI-000008The organization establishes conditions for group membership.4
CCI-000010Require approvals by organization-defined personnel or roles for requests to create accounts.5, 4
CCI-000011Create, enable, modify, disable, and remove system accounts in accordance with organization-defined procedures.5, 4
CCI-000012Review accounts for compliance with account management requirements per organization-defined frequency.5, 4
CCI-000015Support the management of system accounts using organization-defined automated mechanisms.5, 4
CCI-000016Automatically remove or disable temporary and emergency accounts after an organization-defined time-period for each type of account.5, 4
CCI-000017Disable accounts when the accounts have been inactive for the organization-defined time-period.5, 4
CCI-000018Automatically audit account creation actions.5, 4
CCI-000019Require that users log out in accordance with the organization-defined time-period of expected inactivity or description of when to log out.5, 4
CCI-000217Defines a time period after which inactive accounts are automatically disabled.5, 4
CCI-001358Establish privileged user accounts in accordance with a role-based access scheme; or an attribute-based access scheme.5, 4
CCI-001360Monitor privileged role assignments.5, 4
CCI-001361Defines a time period after which temporary accounts are automatically terminated.5, 4
CCI-001365Defines a time period after which emergency accounts are automatically terminated.5, 4
CCI-001403Automatically audit account modification actions.5, 4
CCI-001404Automatically audit account disabling actions.5, 4
CCI-001405Automatically audit account removal actions.5, 4
CCI-001406Defines a time period of expected inactivity when users are required to log out.5, 4
CCI-001407Administer privileged user accounts in accordance with a role-based access scheme; or an attribute-based access scheme.5, 4
CCI-001547Defines the frequency on which it will review information system accounts for compliance with account management requirements.5, 4
CCI-001682Automatically remove or disable emergency accounts after an organization-defined time period for each type of account.5, 4
CCI-001683The information system notifies organization-defined personnel or roles for account creation actions.4
CCI-001684The information system notifies organization-defined personnel or roles for account modification actions.4
CCI-001685The information system notifies organization-defined personnel or roles for account disabling actions.4
CCI-001686The information system notifies organization-defined personnel or roles for account removal actions.4
CCI-002110The organization defines the information system account types that support the organizational missions/business functions.4
CCI-002111The organization identifies and selects the organization-defined information system account types of information system accounts which support organizational missions/business functions.4
CCI-002112Assign account managers.5, 4
CCI-002113The organization establishes conditions for role membership.4
CCI-002114The organization specifies authorized users of the information system for each account.4
CCI-002115Specify authorized users of the system.5, 4
CCI-002116Specify authorized users of the group.5, 4
CCI-002117Specify authorized users of the role membership.5, 4
CCI-002118Specify authorized access authorizations (i.e., privileges) for each account.5, 4
CCI-002119Specify organization-attributes (as required) for each account on the system.5, 4
CCI-002120Defines the personnel or roles authorized to approve the creation of accounts.5, 4
CCI-002121Defines the procedures to be employed when creating, enabling, modifying, disabling, and removing information system accounts.5, 4
CCI-002122Monitor the use of accounts.5, 4
CCI-002123Notify account managers and organization-defined personnel or roles within an organization-defined time-period when accounts are no longer required.5, 4
CCI-002124Notify account managers and organization-defined personnel or roles within an organization-defined time-period when users are terminated or transferred.5, 4
CCI-002125Notify account managers and organization-defined personnel or roles within an organization-defined time-period when system usage or need-to-know changes for an individual.5, 4
CCI-002126Authorize access to the system based on a valid access authorization.5, 4
CCI-002127Authorize access to the system based on intended system usage.5, 4
CCI-002128Authorize access to the system based on organization-defined attributes (as required).5, 4
CCI-002129Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group.5, 4
CCI-002130Automatically audit account enabling actions.5, 4
CCI-002131The organization defines the personnel or roles to be notified on account creation, modification, enabling, disabling, and removal actions.4
CCI-002132The information system notifies organization-defined personnel or roles for account enabling actions.4
CCI-002133Defines other conditions when users are required to log out.5, 4
CCI-002134Defines a list of dynamic privilege management capabilities to be implemented.5, 4
CCI-002135Implement the organization-defined list of dynamic privilege management capabilities.5, 4
CCI-002136The organization defines the actions to be taken when privileged role assignments are no longer appropriate.4
CCI-002137Revoke access when privileged role or attribute assignments are no longer appropriate.5, 4
CCI-002138Defines the system accounts that can be dynamically created.5, 4
CCI-002139Create organization-defined system accounts dynamically.5, 4
CCI-002140Defines the conditions for establishing shared/group accounts.5, 4
CCI-002141Only permit the use of shared and group accounts that meet organization-defined conditions for establishing shared and group accounts.5, 4
CCI-002142The information system terminates shared/group account credentials when members leave the group.4
CCI-002143Defines the circumstances and/or usage conditions that are to be enforced for organization-defined information system accounts.5, 4
CCI-002144Defines the system accounts that are to be subject to the enforcement of organization-defined circumstances and/or usage conditions.5, 4
CCI-002145Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts.5, 4
CCI-002146Defines atypical usage for which the system accounts are to be monitored.5, 4
CCI-002147Monitor system accounts for organization-defined atypical usage.5, 4
CCI-002148Defines the personnel or roles to whom atypical usage of system accounts are to be reported.5, 4
CCI-002149Report atypical usage of system accounts to organization-defined personnel or roles.5, 4
CCI-002150Defines the time period within which the accounts of users posing a significant risk are to be disabled after discovery of the risk.5, 4
CCI-002151Disable accounts of individuals within an organization-defined time-period of discovery of organization-defined significant risk.5, 4
CCI-003612Define and document the types of accounts allowed and specifically prohibited for use within the system.5
CCI-003613Require organization-defined prerequisites and criteria for group membership.5
CCI-003614Require organization-defined prerequisites and criteria for role membership.5
CCI-003615Defines the prerequisites and criteria for group and role membership.5
CCI-003616Defines the attributes (as required) for each account.5
CCI-003617Create, enable, modify, disable, and remove system accounts in accordance with organization-defined policy.5
CCI-003618Create, enable, modify, disable, and remove system accounts in accordance with organization-defined criteria.5
CCI-003619Create, enable, modify, disable, and remove system accounts in accordance with organization-defined prerequisites.5
CCI-003620Defines the policy to be employed when creating, enabling, modifying, disabling, and removing information system accounts.5
CCI-003621Defines the prerequisites to be employed when creating, enabling, modifying, disabling, and removing information system accounts.5
CCI-003622Defines the criteria to be employed when creating, enabling, modifying, disabling, and removing information system accounts.5
CCI-003623Defines the personnel or roles of whom to notify when accounts are no longer required; when users are terminated or transferred; and when system usage or need-to-know changes for an individual.5
CCI-003624Defines the time period of when to notify account managers for each situation.5
CCI-003625Defines the attributes (as required) for authorizing access to the system.5
CCI-003626Align account management processes with personnel termination and transfer processes.5
CCI-003627Disable accounts when the accounts have expired.5
CCI-003628Disable accounts when the accounts are no longer associated to a user.5
CCI-003629Disable accounts when the accounts are in violation of organizational policy.5
CCI-003630Monitor changes to roles or attributes.5
CCI-003631Defines the system accounts that can be dynamically activated.5
CCI-003632Activate organization-defined system accounts dynamically.5
CCI-003633Defines the system accounts that can be dynamically managed.5
CCI-003634Manage organization-defined system accounts dynamically.5
CCI-003635Defines the system accounts that can be dynamically deactivated.5
CCI-003636Deactivate organization-defined system accounts dynamically.5
CCI-003637Defines the significant risks that may be discovered requiring disabled accounts of individuals.5

STIG rules that implement AC-2

RuleSTIG IDSeverityRequirement
V-205624WN19-00-000300mediumWindows Server 2019 must automatically remove or disable temporary user accounts after 72 hours.
V-205625WN19-AU-000100mediumWindows Server 2019 must be configured to audit Account Management - Security Group Management successes.
V-205626WN19-AU-000110mediumWindows Server 2019 must be configured to audit Account Management - User Account Management successes.
V-205627WN19-AU-000120mediumWindows Server 2019 must be configured to audit Account Management - User Account Management failures.
V-205628WN19-DC-000230mediumWindows Server 2019 must be configured to audit Account Management - Computer Account Management successes.
V-205707WN19-00-000190mediumWindows Server 2019 outdated or unused accounts must be removed or disabled.
V-205710WN19-00-000310mediumWindows Server 2019 must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours.
V-205730WN19-AU-000160mediumWindows Server 2019 must be configured to audit Logon/Logoff - Account Lockout failures.
V-220711WN10-00-000065lowUnused accounts must be disabled or removed from the system after 35 days of inactivity.
V-220750WN10-AU-000030mediumThe system must be configured to audit Account Management - Security Group Management successes.
V-220751WN10-AU-000035mediumThe system must be configured to audit Account Management - User Account Management failures.
V-220752WN10-AU-000040mediumThe system must be configured to audit Account Management - User Account Management successes.
V-230331RHEL-08-020000mediumRHEL 8 temporary user accounts must be provisioned with an expiration time of 72 hours or less.
V-230373RHEL-08-020260mediumRHEL 8 account identifiers (individuals, groups, roles, and devices) must be disabled after 35 days of inactivity.
V-230374RHEL-08-020270mediumRHEL 8 must automatically expire temporary accounts within 72 hours.
V-242381CNTR-K8-000220highThe Kubernetes Controller Manager must create unique service accounts for each work payload.
V-242403CNTR-K8-000700mediumKubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event.
V-253268WN11-00-000065lowUnused accounts must be disabled or removed from the system after 35 days of inactivity.
V-253310WN11-AU-000040mediumThe system must be configured to audit Account Management - User Account Management successes.
V-254256WN22-00-000190mediumWindows Server 2022 outdated or unused accounts must be removed or disabled.
V-254267WN22-00-000300mediumWindows Server 2022 must automatically remove or disable temporary user accounts after 72 hours.
V-254268WN22-00-000310mediumWindows Server 2022 must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours.
V-254303WN22-AU-000100mediumWindows Server 2022 must be configured to audit Account Management - Security Group Management successes.
V-254304WN22-AU-000110mediumWindows Server 2022 must be configured to audit Account Management - User Account Management successes.
V-254305WN22-AU-000120mediumWindows Server 2022 must be configured to audit Account Management - User Account Management failures.
V-254309WN22-AU-000160mediumWindows Server 2022 must be configured to audit Logon/Logoff - Account Lockout failures.
V-254407WN22-DC-000230mediumWindows Server 2022 must be configured to audit Account Management - Computer Account Management successes.
V-258047RHEL-09-411040mediumRHEL 9 must automatically expire temporary accounts within 72 hours.
V-258049RHEL-09-411050mediumRHEL 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
V-258217RHEL-09-654215mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
V-258218RHEL-09-654220mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
V-258219RHEL-09-654225mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
V-258220RHEL-09-654230mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
V-258221RHEL-09-654235mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
V-258222RHEL-09-654240mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
V-258223RHEL-09-654245mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
V-272488RHEL-09-215101mediumRHEL 9 must have the Postfix package installed.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AC-2. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.