San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

AC-3 Access Enforcement

Access Control family. 65 Control Correlation Identifiers map to this control, and 92 STIG rules implement those CCIs.

16CAT I (high)
74CAT II (medium)
2CAT III (low)
65CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to AC-3
Microsoft Windows Server 2019V319
KubernetesV219
Microsoft Windows Server 2022V219
Microsoft Windows 11V211
Microsoft Windows 10V39
Red Hat Enterprise Linux 8V28
Red Hat Enterprise Linux 9V27

Control Correlation Identifiers mapped to AC-3

CCIDefinitionRev
CCI-000021Enforce dual authorization for organization-defined privileged commands and/or other organization-defined actions.5, 4
CCI-000024Prevent access to organization-defined security-relevant information except during secure, non-operable system states.5, 4
CCI-000213Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.5, 4
CCI-001408Defines privileged commands for which dual authorization is to be enforced.5, 4
CCI-001411Defines security-relevant information to which the system prevents access except during secure, non-operable system states.5, 4
CCI-002152Defines other actions necessary for which dual authorization is to be enforced.5, 4
CCI-002153Defines the mandatory access control policies that are to be enforced over all subjects and objects.5, 4
CCI-002154Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy is uniformly enforced across the covered subjects and objects within the system.5, 4
CCI-002155Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from passing the information to unauthorized subjects or objects.5, 4
CCI-002156Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from granting its privileges to other subjects.5, 4
CCI-002157Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from changing one or more security attributes on subjects, objects, the system, or system components.5, 4
CCI-002158Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from choosing the security attributes to be associated with newly created or modified objects.5, 4
CCI-002159Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from choosing the attribute values to be associated with newly created or modified objects.5, 4
CCI-002160Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from changing the rules governing access control.5, 4
CCI-002161Defines subjects which may explicitly be granted organization-defined privileges such that they are not limited by any of the mandatory access control constraints.5, 4
CCI-002162Defines the privileges that may explicitly be granted to organization-defined subjects such that they are not limited by any of the mandatory access control constraints.5, 4
CCI-002163Defines the discretionary access control policies the information system is to enforce over subjects and objects.5, 4
CCI-002164Enforce organization-defined discretionary access control policy that over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information can do one or more of the following: pass the information to any other subjects or objects; grant its privileges to other subjects; change security attributes on subjects, objects, the system, or the system's components; choose the security attributes to be associated with newly created or revised objects; and/or change the rules governing access control.5, 4
CCI-002165Enforce organization-defined discretionary access control policies over defined subjects and objects.5, 4
CCI-002166Defines the role-based access control policies to enforce over all subjects and objects.5, 4
CCI-002167The organization defines the subjects over which the information system will enforce a role-based access control policy.4
CCI-002168The organization defines the objects over which the information system will enforce a role-based access control policy.4
CCI-002169Enforce a role-based access control policy over defined subjects and objects based upon organization-defined roles and users authorized to assume such roles.5, 4
CCI-002170Control access based upon organization-defined roles and users authorized to assume such roles.5, 4
CCI-002171The information system enforces a role-based access control policy over organization-defined subjects.4
CCI-002172The information system enforces a role-based access control policy over organization-defined objects.4
CCI-002173Defines the roles authorized to control access based upon the role-based access control policy.5, 4
CCI-002174Defines the users authorized to control access based upon the role-based access control policy.5, 4
CCI-002175The information system controls access based upon organization-defined roles authorized to assume such roles, employing the organization-defined role-based access control policy.4
CCI-002176The information system controls access based upon organization-defined users authorized to assume such roles, employing the organization-defined role-based access control policy.4
CCI-002177Defines the rules governing the timing of revocation of access authorizations.5, 4
CCI-002178Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects based on organization-defined rules governing the timing of revocations of access authorizations.5, 4
CCI-002179Enforce the revocation of access authorizations resulting from changes to the security attributes of objects based on organization-defined rules governing the timing of revocations of access authorizations.5, 4
CCI-002180Defines the controls the organization-defined system or system component is to provide to protect information released outside the established system boundary.5, 4
CCI-002181Defines system or system components that are to provide organization-defined controls to protect information received outside the established system boundary.5, 4
CCI-002182Release information outside of the established system boundary only if organization-defined system or system components provides organization-defined controls.5, 4
CCI-002183Defines the controls to be used to validate the appropriateness of the information designated for release.5, 4
CCI-002184Release information outside of the established system boundary only if organization-defined controls are used to validate the appropriateness of the information designated for release.5, 4
CCI-002185Defines the conditions on which it will employ an audited override of automated access control mechanisms.5, 4
CCI-002186Employ an audited override of automated access control mechanisms under organization-defined conditions by organization-defined roles.5, 4
CCI-003014Enforce organization-defined mandatory access control policies over all subjects and objects.5, 4
CCI-003015Specifies that organization-defined subjects may explicitly be granted organization-defined privileges such that they are not limited by any defined subset (or all) of the above constraints.5, 4
CCI-003638Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can pass the information to any other subjects or objects.5
CCI-003639Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can grant its privileges to other subjects.5
CCI-003640Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can change security attributes on subjects, objects, the system, or the system's components.5
CCI-003641Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can choose the security attributes to be associated with newly created or revised objects.5
CCI-003642Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can change the rules governing access control.5
CCI-003643Defines the organization-defined roles for which it will employ an audited override of automated access control mechanisms.5
CCI-003644Restrict direct access to data repositories containing organization-defined information types.5
CCI-003645Defines the information types of which to restrict direct access to data repositories.5
CCI-003646Require applications to assert, as part of the installation process, the access needed to the organization-defined system applications and functions.5
CCI-003647Defines the organization-defined system applications and functions as required of the applications as part of the installation process.5
CCI-003648Require applications to provide an enforcement mechanism to prevent other-than-asserted access.5
CCI-003649Approve access changed after initial installations of the application.5
CCI-003650Enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.5
CCI-003651Defines the attributes to assume access permissions for enforcing attribute-based access control policy.5
CCI-003652Enforce attribute-based control access over defined subjects and objects based upon organization-defined attributes to assume access permissions.5
CCI-003653Defines the attributes to assume access permissions for enforcing attribute-based control access.5
CCI-003654Provide organization-defined mechanisms to enable individuals to have access to the following elements of their personally identifiable information: organization-defined elements.5
CCI-003655Defines the mechanisms to be provided for access to elements of personally identifiable information.5
CCI-003656Defines the elements of personally identifiable information.5
CCI-003657Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy.5
CCI-003658Defines the mandatory access control policies that are to be enforced over all subjects and objects.5
CCI-003659Enforce organization-defined discretionary access control policy over the set of covered subjects and objects specified in the policy.5
CCI-003660Defines the discretionary access control policies the system is to enforce over subjects and objects.5

STIG rules that implement AC-3

RuleSTIG IDSeverityRequirement
V-205663WN19-00-000130highWindows Server 2019 local volumes must use a format that supports NTFS attributes.
V-205664WN19-00-000180lowWindows Server 2019 non-administrative accounts or groups must only have print permissions on printer shares.
V-205665WN19-DC-000340mediumWindows Server 2019 Access this computer from the network user right must only be assigned to the Administrators, Authenticated Users, and Enterprise Domain Controllers groups on domain controllers.
V-205666WN19-DC-000360mediumWindows Server 2019 Allow log on through Remote Desktop Services user right must only be assigned to the Administrators group on domain controllers.
V-205667WN19-DC-000370mediumWindows Server 2019 Deny access to this computer from the network user right on domain controllers must be configured to prevent unauthenticated access.
V-205668WN19-DC-000380mediumWindows Server 2019 Deny log on as a batch job user right on domain controllers must be configured to prevent unauthenticated access.
V-205669WN19-DC-000390mediumWindows Server 2019 Deny log on as a service user right must be configured to include no accounts or groups (blank) on domain controllers.
V-205670WN19-DC-000400mediumWindows Server 2019 Deny log on locally user right on domain controllers must be configured to prevent unauthenticated access.
V-205671WN19-MS-000070mediumWindows Server 2019 "Access this computer from the network" user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and standalone or nondomain-joined systems.
V-205672WN19-MS-000080mediumWindows Server 2019 "Deny access to this computer from the network" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and local accounts and from unauthenticated access on all systems.
V-205673WN19-MS-000090mediumWindows Server 2019 "Deny log on as a batch job" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.
V-205674WN19-MS-000100mediumWindows Server 2019 "Deny log on as a service" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts. No other groups or accounts must be assigned this right.
V-205675WN19-MS-000110mediumWindows Server 2019 "Deny log on locally" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.
V-205676WN19-UR-000030mediumWindows Server 2019 Allow log on locally user right must only be assigned to the Administrators group.
V-205734WN19-00-000140mediumWindows Server 2019 permissions for the system drive root directory (usually C:\) must conform to minimum requirements.
V-205735WN19-00-000150mediumWindows Server 2019 permissions for program file directories must conform to minimum requirements.
V-205736WN19-00-000160mediumWindows Server 2019 permissions for the Windows installation directory must conform to minimum requirements.
V-220708WN10-00-000050highLocal volumes must be formatted using NTFS.
V-220717WN10-00-000095mediumPermissions for system files and directories must conform to minimum requirements.
V-220957WN10-UR-000010mediumThe Access this computer from the network user right must only be assigned to the Administrators and Remote Desktop Users groups.
V-220959WN10-UR-000025mediumThe Allow log on locally user right must only be assigned to the Administrators and Users groups.
V-220968WN10-UR-000070mediumThe Deny access to this computer from the network user right on workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.
V-220969WN10-UR-000075mediumThe "Deny log on as a batch job" user right on domain-joined workstations must be configured to prevent access from highly privileged domain accounts.
V-220970WN10-UR-000080mediumThe Deny log on as a service user right on Windows 10 domain-joined workstations must be configured to prevent access from highly privileged domain accounts.
V-220971WN10-UR-000085mediumThe Deny log on locally user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems.
V-220972WN10-UR-000090mediumThe Deny log on through Remote Desktop Services user right on Windows 10 workstations must at a minimum be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.
V-230234RHEL-08-010140highRHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance.
V-230235RHEL-08-010150highRHEL 8 operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes.
V-230236RHEL-08-010151mediumRHEL 8 operating systems must require authentication upon booting into rescue mode.
V-230267RHEL-08-010373mediumRHEL 8 must enable kernel parameters to enforce discretionary access control on symlinks.
V-230268RHEL-08-010374mediumRHEL 8 must enable kernel parameters to enforce discretionary access control on hardlinks.
V-242382CNTR-K8-000270mediumThe Kubernetes API Server must enable Node,RBAC as the authorization mode.
V-242384CNTR-K8-000300mediumThe Kubernetes Scheduler must have secure binding.
V-242385CNTR-K8-000310mediumThe Kubernetes Controller Manager must have secure binding.
V-242386CNTR-K8-000320highThe Kubernetes API server must have the insecure port flag disabled.
V-242387CNTR-K8-000330highThe Kubernetes Kubelet must have the "readOnlyPort" flag disabled.
V-242388CNTR-K8-000340highThe Kubernetes API server must have the insecure bind address not set.
V-242389CNTR-K8-000350mediumThe Kubernetes API server must have the secure port set.
V-242390CNTR-K8-000360highThe Kubernetes API server must have anonymous authentication disabled.
V-242391CNTR-K8-000370highThe Kubernetes Kubelet must have anonymous authentication disabled.
V-242392CNTR-K8-000380highThe Kubernetes kubelet must enable explicit authorization.
V-242393CNTR-K8-000400mediumKubernetes Worker Nodes must not have sshd service running.
V-242394CNTR-K8-000410mediumKubernetes Worker Nodes must not have the sshd service enabled.
V-242395CNTR-K8-000420mediumKubernetes dashboard must not be enabled.
V-242396CNTR-K8-000430mediumKubernetes Kubectl cp command must give expected access and results.
V-242397CNTR-K8-000440highThe Kubernetes kubelet staticPodPath must not enable static pods.
V-242398CNTR-K8-000450mediumKubernetes DynamicAuditing must not be enabled.
V-242399CNTR-K8-000460mediumKubernetes DynamicKubeletConfig must not be enabled.
V-242400CNTR-K8-000470mediumThe Kubernetes API server must have Alpha APIs disabled.
V-244521RHEL-08-010141mediumRHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require a unique superusers name upon booting into single-user mode and maintenance.
V-244522RHEL-08-010149mediumRHEL 8 operating systems booted with a BIOS must require a unique superusers name upon booting into single-user and maintenance modes.
V-244523RHEL-08-010152mediumRHEL 8 operating systems must require authentication upon booting into emergency mode.
V-253265WN11-00-000050highLocal volumes must be formatted using NTFS.
V-253269WN11-00-000070highOnly accounts responsible for the administration of a system must have Administrator rights on the system.
V-253271WN11-00-000080mediumOnly authorized user accounts must be allowed to create or run virtual machines on Windows 11 systems.
V-253274WN11-00-000095mediumPermissions for system files and directories must conform to minimum requirements.
V-253480WN11-UR-000010mediumThe "Access this computer from the network" user right must only be assigned to the Administrators and Remote Desktop Users groups.
V-253482WN11-UR-000025mediumThe "Allow log on locally" user right must only be assigned to the Administrators and Users groups.
V-253491WN11-UR-000070mediumThe "Deny access to this computer from the network" user right on workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.
V-253492WN11-UR-000075mediumThe "Deny log on as a batch job" user right on domain-joined workstations must be configured to prevent access from highly privileged domain accounts.
V-253493WN11-UR-000080mediumThe "Deny log on as a service" user right on Windows 11 domain-joined workstations must be configured to prevent access from highly privileged domain accounts.
V-253494WN11-UR-000085mediumThe "Deny log on locally" user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems.
V-253495WN11-UR-000090mediumThe "Deny log on through Remote Desktop Services" user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.
V-254250WN22-00-000130highWindows Server 2022 local volumes must use a format that supports NTFS attributes.
V-254251WN22-00-000140mediumWindows Server 2022 permissions for the system drive root directory (usually C:\) must conform to minimum requirements.
V-254252WN22-00-000150mediumWindows Server 2022 permissions for program file directories must conform to minimum requirements.
V-254253WN22-00-000160mediumWindows Server 2022 permissions for the Windows installation directory must conform to minimum requirements.
V-254255WN22-00-000180lowWindows Server 2022 nonadministrative accounts or groups must only have print permissions on printer shares.
V-254418WN22-DC-000340mediumWindows Server 2022 Access this computer from the network user right must only be assigned to the Administrators, Authenticated Users, and Enterprise Domain Controllers groups on domain controllers.
V-254420WN22-DC-000360mediumWindows Server 2022 Allow log on through Remote Desktop Services user right must only be assigned to the Administrators group on domain controllers.
V-254421WN22-DC-000370mediumWindows Server 2022 Deny access to this computer from the network user right on domain controllers must be configured to prevent unauthenticated access.
V-254422WN22-DC-000380mediumWindows Server 2022 Deny log on as a batch job user right on domain controllers must be configured to prevent unauthenticated access.
V-254423WN22-DC-000390mediumWindows Server 2022 Deny log on as a service user right must be configured to include no accounts or groups (blank) on domain controllers.
V-254424WN22-DC-000400mediumWindows Server 2022 Deny log on locally user right on domain controllers must be configured to prevent unauthenticated access.
V-254434WN22-MS-000070mediumWindows Server 2022 Access this computer from the network user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and standalone or nondomain-joined systems.
V-254435WN22-MS-000080mediumWindows Server 2022 Deny access to this computer from the network user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and local accounts and from unauthenticated access on all systems.
V-254436WN22-MS-000090mediumWindows Server 2022 Deny log on as a batch job user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.
V-254437WN22-MS-000100mediumWindows Server 2022 Deny log on as a service user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts. No other groups or accounts must be assigned this right.
V-254438WN22-MS-000110mediumWindows Server 2022 Deny log on locally user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.
V-254493WN22-UR-000030mediumWindows Server 2022 Allow log on locally user right must only be assigned to the Administrators group.
V-257787RHEL-09-212010mediumRHEL 9 must require a boot loader superuser password.
V-257789RHEL-09-212020highRHEL 9 must require a unique superusers name upon booting into single-user and maintenance modes.
V-257801RHEL-09-213030mediumRHEL 9 must enable kernel parameters to enforce discretionary access control on hardlinks.
V-257802RHEL-09-213035mediumRHEL 9 must enable kernel parameters to enforce discretionary access control on symlinks.
V-258088RHEL-09-432035mediumRHEL 9 must restrict the use of the "su" command.
V-258128RHEL-09-611195mediumRHEL 9 must require authentication to access emergency mode.
V-258129RHEL-09-611200mediumRHEL 9 must require authentication to access single-user mode.
V-271426WN22-DC-000405mediumWindows Server 2022 must be configured for certificate-based authentication for domain controllers.
V-271427WN22-DC-000406mediumWindows Server 2022 must be configured for name-based strong mappings for certificates.
V-271428WN19-DC-000391mediumWindows Server 2019 must be configured for certificate-based authentication for domain controllers.
V-271429WN19-DC-000401mediumWindows Server 2019 must be configured for named-based strong mappings for certificates.
V-274882CNTR-K8-001162highKubernetes Secrets must be encrypted at rest.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AC-3. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.