AC-2 Account Management
Access Control family. 93 Control Correlation Identifiers map to this control, and 37 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to AC-2 |
|---|---|---|
| Red Hat Enterprise Linux 9 | V2 | 10 |
| Microsoft Windows Server 2019 | V3 | 8 |
| Microsoft Windows Server 2022 | V2 | 8 |
| Microsoft Windows 10 | V3 | 4 |
| Red Hat Enterprise Linux 8 | V2 | 3 |
| Kubernetes | V2 | 2 |
| Microsoft Windows 11 | V2 | 2 |
Control Correlation Identifiers mapped to AC-2
| CCI | Definition | Rev |
|---|---|---|
| CCI-000008 | The organization establishes conditions for group membership. | 4 |
| CCI-000010 | Require approvals by organization-defined personnel or roles for requests to create accounts. | 5, 4 |
| CCI-000011 | Create, enable, modify, disable, and remove system accounts in accordance with organization-defined procedures. | 5, 4 |
| CCI-000012 | Review accounts for compliance with account management requirements per organization-defined frequency. | 5, 4 |
| CCI-000015 | Support the management of system accounts using organization-defined automated mechanisms. | 5, 4 |
| CCI-000016 | Automatically remove or disable temporary and emergency accounts after an organization-defined time-period for each type of account. | 5, 4 |
| CCI-000017 | Disable accounts when the accounts have been inactive for the organization-defined time-period. | 5, 4 |
| CCI-000018 | Automatically audit account creation actions. | 5, 4 |
| CCI-000019 | Require that users log out in accordance with the organization-defined time-period of expected inactivity or description of when to log out. | 5, 4 |
| CCI-000217 | Defines a time period after which inactive accounts are automatically disabled. | 5, 4 |
| CCI-001358 | Establish privileged user accounts in accordance with a role-based access scheme; or an attribute-based access scheme. | 5, 4 |
| CCI-001360 | Monitor privileged role assignments. | 5, 4 |
| CCI-001361 | Defines a time period after which temporary accounts are automatically terminated. | 5, 4 |
| CCI-001365 | Defines a time period after which emergency accounts are automatically terminated. | 5, 4 |
| CCI-001403 | Automatically audit account modification actions. | 5, 4 |
| CCI-001404 | Automatically audit account disabling actions. | 5, 4 |
| CCI-001405 | Automatically audit account removal actions. | 5, 4 |
| CCI-001406 | Defines a time period of expected inactivity when users are required to log out. | 5, 4 |
| CCI-001407 | Administer privileged user accounts in accordance with a role-based access scheme; or an attribute-based access scheme. | 5, 4 |
| CCI-001547 | Defines the frequency on which it will review information system accounts for compliance with account management requirements. | 5, 4 |
| CCI-001682 | Automatically remove or disable emergency accounts after an organization-defined time period for each type of account. | 5, 4 |
| CCI-001683 | The information system notifies organization-defined personnel or roles for account creation actions. | 4 |
| CCI-001684 | The information system notifies organization-defined personnel or roles for account modification actions. | 4 |
| CCI-001685 | The information system notifies organization-defined personnel or roles for account disabling actions. | 4 |
| CCI-001686 | The information system notifies organization-defined personnel or roles for account removal actions. | 4 |
| CCI-002110 | The organization defines the information system account types that support the organizational missions/business functions. | 4 |
| CCI-002111 | The organization identifies and selects the organization-defined information system account types of information system accounts which support organizational missions/business functions. | 4 |
| CCI-002112 | Assign account managers. | 5, 4 |
| CCI-002113 | The organization establishes conditions for role membership. | 4 |
| CCI-002114 | The organization specifies authorized users of the information system for each account. | 4 |
| CCI-002115 | Specify authorized users of the system. | 5, 4 |
| CCI-002116 | Specify authorized users of the group. | 5, 4 |
| CCI-002117 | Specify authorized users of the role membership. | 5, 4 |
| CCI-002118 | Specify authorized access authorizations (i.e., privileges) for each account. | 5, 4 |
| CCI-002119 | Specify organization-attributes (as required) for each account on the system. | 5, 4 |
| CCI-002120 | Defines the personnel or roles authorized to approve the creation of accounts. | 5, 4 |
| CCI-002121 | Defines the procedures to be employed when creating, enabling, modifying, disabling, and removing information system accounts. | 5, 4 |
| CCI-002122 | Monitor the use of accounts. | 5, 4 |
| CCI-002123 | Notify account managers and organization-defined personnel or roles within an organization-defined time-period when accounts are no longer required. | 5, 4 |
| CCI-002124 | Notify account managers and organization-defined personnel or roles within an organization-defined time-period when users are terminated or transferred. | 5, 4 |
| CCI-002125 | Notify account managers and organization-defined personnel or roles within an organization-defined time-period when system usage or need-to-know changes for an individual. | 5, 4 |
| CCI-002126 | Authorize access to the system based on a valid access authorization. | 5, 4 |
| CCI-002127 | Authorize access to the system based on intended system usage. | 5, 4 |
| CCI-002128 | Authorize access to the system based on organization-defined attributes (as required). | 5, 4 |
| CCI-002129 | Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group. | 5, 4 |
| CCI-002130 | Automatically audit account enabling actions. | 5, 4 |
| CCI-002131 | The organization defines the personnel or roles to be notified on account creation, modification, enabling, disabling, and removal actions. | 4 |
| CCI-002132 | The information system notifies organization-defined personnel or roles for account enabling actions. | 4 |
| CCI-002133 | Defines other conditions when users are required to log out. | 5, 4 |
| CCI-002134 | Defines a list of dynamic privilege management capabilities to be implemented. | 5, 4 |
| CCI-002135 | Implement the organization-defined list of dynamic privilege management capabilities. | 5, 4 |
| CCI-002136 | The organization defines the actions to be taken when privileged role assignments are no longer appropriate. | 4 |
| CCI-002137 | Revoke access when privileged role or attribute assignments are no longer appropriate. | 5, 4 |
| CCI-002138 | Defines the system accounts that can be dynamically created. | 5, 4 |
| CCI-002139 | Create organization-defined system accounts dynamically. | 5, 4 |
| CCI-002140 | Defines the conditions for establishing shared/group accounts. | 5, 4 |
| CCI-002141 | Only permit the use of shared and group accounts that meet organization-defined conditions for establishing shared and group accounts. | 5, 4 |
| CCI-002142 | The information system terminates shared/group account credentials when members leave the group. | 4 |
| CCI-002143 | Defines the circumstances and/or usage conditions that are to be enforced for organization-defined information system accounts. | 5, 4 |
| CCI-002144 | Defines the system accounts that are to be subject to the enforcement of organization-defined circumstances and/or usage conditions. | 5, 4 |
| CCI-002145 | Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts. | 5, 4 |
| CCI-002146 | Defines atypical usage for which the system accounts are to be monitored. | 5, 4 |
| CCI-002147 | Monitor system accounts for organization-defined atypical usage. | 5, 4 |
| CCI-002148 | Defines the personnel or roles to whom atypical usage of system accounts are to be reported. | 5, 4 |
| CCI-002149 | Report atypical usage of system accounts to organization-defined personnel or roles. | 5, 4 |
| CCI-002150 | Defines the time period within which the accounts of users posing a significant risk are to be disabled after discovery of the risk. | 5, 4 |
| CCI-002151 | Disable accounts of individuals within an organization-defined time-period of discovery of organization-defined significant risk. | 5, 4 |
| CCI-003612 | Define and document the types of accounts allowed and specifically prohibited for use within the system. | 5 |
| CCI-003613 | Require organization-defined prerequisites and criteria for group membership. | 5 |
| CCI-003614 | Require organization-defined prerequisites and criteria for role membership. | 5 |
| CCI-003615 | Defines the prerequisites and criteria for group and role membership. | 5 |
| CCI-003616 | Defines the attributes (as required) for each account. | 5 |
| CCI-003617 | Create, enable, modify, disable, and remove system accounts in accordance with organization-defined policy. | 5 |
| CCI-003618 | Create, enable, modify, disable, and remove system accounts in accordance with organization-defined criteria. | 5 |
| CCI-003619 | Create, enable, modify, disable, and remove system accounts in accordance with organization-defined prerequisites. | 5 |
| CCI-003620 | Defines the policy to be employed when creating, enabling, modifying, disabling, and removing information system accounts. | 5 |
| CCI-003621 | Defines the prerequisites to be employed when creating, enabling, modifying, disabling, and removing information system accounts. | 5 |
| CCI-003622 | Defines the criteria to be employed when creating, enabling, modifying, disabling, and removing information system accounts. | 5 |
| CCI-003623 | Defines the personnel or roles of whom to notify when accounts are no longer required; when users are terminated or transferred; and when system usage or need-to-know changes for an individual. | 5 |
| CCI-003624 | Defines the time period of when to notify account managers for each situation. | 5 |
| CCI-003625 | Defines the attributes (as required) for authorizing access to the system. | 5 |
| CCI-003626 | Align account management processes with personnel termination and transfer processes. | 5 |
| CCI-003627 | Disable accounts when the accounts have expired. | 5 |
| CCI-003628 | Disable accounts when the accounts are no longer associated to a user. | 5 |
| CCI-003629 | Disable accounts when the accounts are in violation of organizational policy. | 5 |
| CCI-003630 | Monitor changes to roles or attributes. | 5 |
| CCI-003631 | Defines the system accounts that can be dynamically activated. | 5 |
| CCI-003632 | Activate organization-defined system accounts dynamically. | 5 |
| CCI-003633 | Defines the system accounts that can be dynamically managed. | 5 |
| CCI-003634 | Manage organization-defined system accounts dynamically. | 5 |
| CCI-003635 | Defines the system accounts that can be dynamically deactivated. | 5 |
| CCI-003636 | Deactivate organization-defined system accounts dynamically. | 5 |
| CCI-003637 | Defines the significant risks that may be discovered requiring disabled accounts of individuals. | 5 |
STIG rules that implement AC-2
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205624 | WN19-00-000300 | medium | Windows Server 2019 must automatically remove or disable temporary user accounts after 72 hours. |
| V-205625 | WN19-AU-000100 | medium | Windows Server 2019 must be configured to audit Account Management - Security Group Management successes. |
| V-205626 | WN19-AU-000110 | medium | Windows Server 2019 must be configured to audit Account Management - User Account Management successes. |
| V-205627 | WN19-AU-000120 | medium | Windows Server 2019 must be configured to audit Account Management - User Account Management failures. |
| V-205628 | WN19-DC-000230 | medium | Windows Server 2019 must be configured to audit Account Management - Computer Account Management successes. |
| V-205707 | WN19-00-000190 | medium | Windows Server 2019 outdated or unused accounts must be removed or disabled. |
| V-205710 | WN19-00-000310 | medium | Windows Server 2019 must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours. |
| V-205730 | WN19-AU-000160 | medium | Windows Server 2019 must be configured to audit Logon/Logoff - Account Lockout failures. |
| V-220711 | WN10-00-000065 | low | Unused accounts must be disabled or removed from the system after 35 days of inactivity. |
| V-220750 | WN10-AU-000030 | medium | The system must be configured to audit Account Management - Security Group Management successes. |
| V-220751 | WN10-AU-000035 | medium | The system must be configured to audit Account Management - User Account Management failures. |
| V-220752 | WN10-AU-000040 | medium | The system must be configured to audit Account Management - User Account Management successes. |
| V-230331 | RHEL-08-020000 | medium | RHEL 8 temporary user accounts must be provisioned with an expiration time of 72 hours or less. |
| V-230373 | RHEL-08-020260 | medium | RHEL 8 account identifiers (individuals, groups, roles, and devices) must be disabled after 35 days of inactivity. |
| V-230374 | RHEL-08-020270 | medium | RHEL 8 must automatically expire temporary accounts within 72 hours. |
| V-242381 | CNTR-K8-000220 | high | The Kubernetes Controller Manager must create unique service accounts for each work payload. |
| V-242403 | CNTR-K8-000700 | medium | Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event. |
| V-253268 | WN11-00-000065 | low | Unused accounts must be disabled or removed from the system after 35 days of inactivity. |
| V-253310 | WN11-AU-000040 | medium | The system must be configured to audit Account Management - User Account Management successes. |
| V-254256 | WN22-00-000190 | medium | Windows Server 2022 outdated or unused accounts must be removed or disabled. |
| V-254267 | WN22-00-000300 | medium | Windows Server 2022 must automatically remove or disable temporary user accounts after 72 hours. |
| V-254268 | WN22-00-000310 | medium | Windows Server 2022 must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours. |
| V-254303 | WN22-AU-000100 | medium | Windows Server 2022 must be configured to audit Account Management - Security Group Management successes. |
| V-254304 | WN22-AU-000110 | medium | Windows Server 2022 must be configured to audit Account Management - User Account Management successes. |
| V-254305 | WN22-AU-000120 | medium | Windows Server 2022 must be configured to audit Account Management - User Account Management failures. |
| V-254309 | WN22-AU-000160 | medium | Windows Server 2022 must be configured to audit Logon/Logoff - Account Lockout failures. |
| V-254407 | WN22-DC-000230 | medium | Windows Server 2022 must be configured to audit Account Management - Computer Account Management successes. |
| V-258047 | RHEL-09-411040 | medium | RHEL 9 must automatically expire temporary accounts within 72 hours. |
| V-258049 | RHEL-09-411050 | medium | RHEL 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. |
| V-258217 | RHEL-09-654215 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. |
| V-258218 | RHEL-09-654220 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory. |
| V-258219 | RHEL-09-654225 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. |
| V-258220 | RHEL-09-654230 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. |
| V-258221 | RHEL-09-654235 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd. |
| V-258222 | RHEL-09-654240 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. |
| V-258223 | RHEL-09-654245 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. |
| V-272488 | RHEL-09-215101 | medium | RHEL 9 must have the Postfix package installed. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AC-2. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.