AC-3 Access Enforcement
Access Control family. 65 Control Correlation Identifiers map to this control, and 92 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to AC-3 |
|---|---|---|
| Microsoft Windows Server 2019 | V3 | 19 |
| Kubernetes | V2 | 19 |
| Microsoft Windows Server 2022 | V2 | 19 |
| Microsoft Windows 11 | V2 | 11 |
| Microsoft Windows 10 | V3 | 9 |
| Red Hat Enterprise Linux 8 | V2 | 8 |
| Red Hat Enterprise Linux 9 | V2 | 7 |
Control Correlation Identifiers mapped to AC-3
| CCI | Definition | Rev |
|---|---|---|
| CCI-000021 | Enforce dual authorization for organization-defined privileged commands and/or other organization-defined actions. | 5, 4 |
| CCI-000024 | Prevent access to organization-defined security-relevant information except during secure, non-operable system states. | 5, 4 |
| CCI-000213 | Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. | 5, 4 |
| CCI-001408 | Defines privileged commands for which dual authorization is to be enforced. | 5, 4 |
| CCI-001411 | Defines security-relevant information to which the system prevents access except during secure, non-operable system states. | 5, 4 |
| CCI-002152 | Defines other actions necessary for which dual authorization is to be enforced. | 5, 4 |
| CCI-002153 | Defines the mandatory access control policies that are to be enforced over all subjects and objects. | 5, 4 |
| CCI-002154 | Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy is uniformly enforced across the covered subjects and objects within the system. | 5, 4 |
| CCI-002155 | Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from passing the information to unauthorized subjects or objects. | 5, 4 |
| CCI-002156 | Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from granting its privileges to other subjects. | 5, 4 |
| CCI-002157 | Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from changing one or more security attributes on subjects, objects, the system, or system components. | 5, 4 |
| CCI-002158 | Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from choosing the security attributes to be associated with newly created or modified objects. | 5, 4 |
| CCI-002159 | Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from choosing the attribute values to be associated with newly created or modified objects. | 5, 4 |
| CCI-002160 | Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from changing the rules governing access control. | 5, 4 |
| CCI-002161 | Defines subjects which may explicitly be granted organization-defined privileges such that they are not limited by any of the mandatory access control constraints. | 5, 4 |
| CCI-002162 | Defines the privileges that may explicitly be granted to organization-defined subjects such that they are not limited by any of the mandatory access control constraints. | 5, 4 |
| CCI-002163 | Defines the discretionary access control policies the information system is to enforce over subjects and objects. | 5, 4 |
| CCI-002164 | Enforce organization-defined discretionary access control policy that over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information can do one or more of the following: pass the information to any other subjects or objects; grant its privileges to other subjects; change security attributes on subjects, objects, the system, or the system's components; choose the security attributes to be associated with newly created or revised objects; and/or change the rules governing access control. | 5, 4 |
| CCI-002165 | Enforce organization-defined discretionary access control policies over defined subjects and objects. | 5, 4 |
| CCI-002166 | Defines the role-based access control policies to enforce over all subjects and objects. | 5, 4 |
| CCI-002167 | The organization defines the subjects over which the information system will enforce a role-based access control policy. | 4 |
| CCI-002168 | The organization defines the objects over which the information system will enforce a role-based access control policy. | 4 |
| CCI-002169 | Enforce a role-based access control policy over defined subjects and objects based upon organization-defined roles and users authorized to assume such roles. | 5, 4 |
| CCI-002170 | Control access based upon organization-defined roles and users authorized to assume such roles. | 5, 4 |
| CCI-002171 | The information system enforces a role-based access control policy over organization-defined subjects. | 4 |
| CCI-002172 | The information system enforces a role-based access control policy over organization-defined objects. | 4 |
| CCI-002173 | Defines the roles authorized to control access based upon the role-based access control policy. | 5, 4 |
| CCI-002174 | Defines the users authorized to control access based upon the role-based access control policy. | 5, 4 |
| CCI-002175 | The information system controls access based upon organization-defined roles authorized to assume such roles, employing the organization-defined role-based access control policy. | 4 |
| CCI-002176 | The information system controls access based upon organization-defined users authorized to assume such roles, employing the organization-defined role-based access control policy. | 4 |
| CCI-002177 | Defines the rules governing the timing of revocation of access authorizations. | 5, 4 |
| CCI-002178 | Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects based on organization-defined rules governing the timing of revocations of access authorizations. | 5, 4 |
| CCI-002179 | Enforce the revocation of access authorizations resulting from changes to the security attributes of objects based on organization-defined rules governing the timing of revocations of access authorizations. | 5, 4 |
| CCI-002180 | Defines the controls the organization-defined system or system component is to provide to protect information released outside the established system boundary. | 5, 4 |
| CCI-002181 | Defines system or system components that are to provide organization-defined controls to protect information received outside the established system boundary. | 5, 4 |
| CCI-002182 | Release information outside of the established system boundary only if organization-defined system or system components provides organization-defined controls. | 5, 4 |
| CCI-002183 | Defines the controls to be used to validate the appropriateness of the information designated for release. | 5, 4 |
| CCI-002184 | Release information outside of the established system boundary only if organization-defined controls are used to validate the appropriateness of the information designated for release. | 5, 4 |
| CCI-002185 | Defines the conditions on which it will employ an audited override of automated access control mechanisms. | 5, 4 |
| CCI-002186 | Employ an audited override of automated access control mechanisms under organization-defined conditions by organization-defined roles. | 5, 4 |
| CCI-003014 | Enforce organization-defined mandatory access control policies over all subjects and objects. | 5, 4 |
| CCI-003015 | Specifies that organization-defined subjects may explicitly be granted organization-defined privileges such that they are not limited by any defined subset (or all) of the above constraints. | 5, 4 |
| CCI-003638 | Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can pass the information to any other subjects or objects. | 5 |
| CCI-003639 | Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can grant its privileges to other subjects. | 5 |
| CCI-003640 | Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can change security attributes on subjects, objects, the system, or the system's components. | 5 |
| CCI-003641 | Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can choose the security attributes to be associated with newly created or revised objects. | 5 |
| CCI-003642 | Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can change the rules governing access control. | 5 |
| CCI-003643 | Defines the organization-defined roles for which it will employ an audited override of automated access control mechanisms. | 5 |
| CCI-003644 | Restrict direct access to data repositories containing organization-defined information types. | 5 |
| CCI-003645 | Defines the information types of which to restrict direct access to data repositories. | 5 |
| CCI-003646 | Require applications to assert, as part of the installation process, the access needed to the organization-defined system applications and functions. | 5 |
| CCI-003647 | Defines the organization-defined system applications and functions as required of the applications as part of the installation process. | 5 |
| CCI-003648 | Require applications to provide an enforcement mechanism to prevent other-than-asserted access. | 5 |
| CCI-003649 | Approve access changed after initial installations of the application. | 5 |
| CCI-003650 | Enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions. | 5 |
| CCI-003651 | Defines the attributes to assume access permissions for enforcing attribute-based access control policy. | 5 |
| CCI-003652 | Enforce attribute-based control access over defined subjects and objects based upon organization-defined attributes to assume access permissions. | 5 |
| CCI-003653 | Defines the attributes to assume access permissions for enforcing attribute-based control access. | 5 |
| CCI-003654 | Provide organization-defined mechanisms to enable individuals to have access to the following elements of their personally identifiable information: organization-defined elements. | 5 |
| CCI-003655 | Defines the mechanisms to be provided for access to elements of personally identifiable information. | 5 |
| CCI-003656 | Defines the elements of personally identifiable information. | 5 |
| CCI-003657 | Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy. | 5 |
| CCI-003658 | Defines the mandatory access control policies that are to be enforced over all subjects and objects. | 5 |
| CCI-003659 | Enforce organization-defined discretionary access control policy over the set of covered subjects and objects specified in the policy. | 5 |
| CCI-003660 | Defines the discretionary access control policies the system is to enforce over subjects and objects. | 5 |
STIG rules that implement AC-3
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205663 | WN19-00-000130 | high | Windows Server 2019 local volumes must use a format that supports NTFS attributes. |
| V-205664 | WN19-00-000180 | low | Windows Server 2019 non-administrative accounts or groups must only have print permissions on printer shares. |
| V-205665 | WN19-DC-000340 | medium | Windows Server 2019 Access this computer from the network user right must only be assigned to the Administrators, Authenticated Users, and Enterprise Domain Controllers groups on domain controllers. |
| V-205666 | WN19-DC-000360 | medium | Windows Server 2019 Allow log on through Remote Desktop Services user right must only be assigned to the Administrators group on domain controllers. |
| V-205667 | WN19-DC-000370 | medium | Windows Server 2019 Deny access to this computer from the network user right on domain controllers must be configured to prevent unauthenticated access. |
| V-205668 | WN19-DC-000380 | medium | Windows Server 2019 Deny log on as a batch job user right on domain controllers must be configured to prevent unauthenticated access. |
| V-205669 | WN19-DC-000390 | medium | Windows Server 2019 Deny log on as a service user right must be configured to include no accounts or groups (blank) on domain controllers. |
| V-205670 | WN19-DC-000400 | medium | Windows Server 2019 Deny log on locally user right on domain controllers must be configured to prevent unauthenticated access. |
| V-205671 | WN19-MS-000070 | medium | Windows Server 2019 "Access this computer from the network" user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and standalone or nondomain-joined systems. |
| V-205672 | WN19-MS-000080 | medium | Windows Server 2019 "Deny access to this computer from the network" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and local accounts and from unauthenticated access on all systems. |
| V-205673 | WN19-MS-000090 | medium | Windows Server 2019 "Deny log on as a batch job" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems. |
| V-205674 | WN19-MS-000100 | medium | Windows Server 2019 "Deny log on as a service" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts. No other groups or accounts must be assigned this right. |
| V-205675 | WN19-MS-000110 | medium | Windows Server 2019 "Deny log on locally" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems. |
| V-205676 | WN19-UR-000030 | medium | Windows Server 2019 Allow log on locally user right must only be assigned to the Administrators group. |
| V-205734 | WN19-00-000140 | medium | Windows Server 2019 permissions for the system drive root directory (usually C:\) must conform to minimum requirements. |
| V-205735 | WN19-00-000150 | medium | Windows Server 2019 permissions for program file directories must conform to minimum requirements. |
| V-205736 | WN19-00-000160 | medium | Windows Server 2019 permissions for the Windows installation directory must conform to minimum requirements. |
| V-220708 | WN10-00-000050 | high | Local volumes must be formatted using NTFS. |
| V-220717 | WN10-00-000095 | medium | Permissions for system files and directories must conform to minimum requirements. |
| V-220957 | WN10-UR-000010 | medium | The Access this computer from the network user right must only be assigned to the Administrators and Remote Desktop Users groups. |
| V-220959 | WN10-UR-000025 | medium | The Allow log on locally user right must only be assigned to the Administrators and Users groups. |
| V-220968 | WN10-UR-000070 | medium | The Deny access to this computer from the network user right on workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems. |
| V-220969 | WN10-UR-000075 | medium | The "Deny log on as a batch job" user right on domain-joined workstations must be configured to prevent access from highly privileged domain accounts. |
| V-220970 | WN10-UR-000080 | medium | The Deny log on as a service user right on Windows 10 domain-joined workstations must be configured to prevent access from highly privileged domain accounts. |
| V-220971 | WN10-UR-000085 | medium | The Deny log on locally user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems. |
| V-220972 | WN10-UR-000090 | medium | The Deny log on through Remote Desktop Services user right on Windows 10 workstations must at a minimum be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems. |
| V-230234 | RHEL-08-010140 | high | RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance. |
| V-230235 | RHEL-08-010150 | high | RHEL 8 operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes. |
| V-230236 | RHEL-08-010151 | medium | RHEL 8 operating systems must require authentication upon booting into rescue mode. |
| V-230267 | RHEL-08-010373 | medium | RHEL 8 must enable kernel parameters to enforce discretionary access control on symlinks. |
| V-230268 | RHEL-08-010374 | medium | RHEL 8 must enable kernel parameters to enforce discretionary access control on hardlinks. |
| V-242382 | CNTR-K8-000270 | medium | The Kubernetes API Server must enable Node,RBAC as the authorization mode. |
| V-242384 | CNTR-K8-000300 | medium | The Kubernetes Scheduler must have secure binding. |
| V-242385 | CNTR-K8-000310 | medium | The Kubernetes Controller Manager must have secure binding. |
| V-242386 | CNTR-K8-000320 | high | The Kubernetes API server must have the insecure port flag disabled. |
| V-242387 | CNTR-K8-000330 | high | The Kubernetes Kubelet must have the "readOnlyPort" flag disabled. |
| V-242388 | CNTR-K8-000340 | high | The Kubernetes API server must have the insecure bind address not set. |
| V-242389 | CNTR-K8-000350 | medium | The Kubernetes API server must have the secure port set. |
| V-242390 | CNTR-K8-000360 | high | The Kubernetes API server must have anonymous authentication disabled. |
| V-242391 | CNTR-K8-000370 | high | The Kubernetes Kubelet must have anonymous authentication disabled. |
| V-242392 | CNTR-K8-000380 | high | The Kubernetes kubelet must enable explicit authorization. |
| V-242393 | CNTR-K8-000400 | medium | Kubernetes Worker Nodes must not have sshd service running. |
| V-242394 | CNTR-K8-000410 | medium | Kubernetes Worker Nodes must not have the sshd service enabled. |
| V-242395 | CNTR-K8-000420 | medium | Kubernetes dashboard must not be enabled. |
| V-242396 | CNTR-K8-000430 | medium | Kubernetes Kubectl cp command must give expected access and results. |
| V-242397 | CNTR-K8-000440 | high | The Kubernetes kubelet staticPodPath must not enable static pods. |
| V-242398 | CNTR-K8-000450 | medium | Kubernetes DynamicAuditing must not be enabled. |
| V-242399 | CNTR-K8-000460 | medium | Kubernetes DynamicKubeletConfig must not be enabled. |
| V-242400 | CNTR-K8-000470 | medium | The Kubernetes API server must have Alpha APIs disabled. |
| V-244521 | RHEL-08-010141 | medium | RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require a unique superusers name upon booting into single-user mode and maintenance. |
| V-244522 | RHEL-08-010149 | medium | RHEL 8 operating systems booted with a BIOS must require a unique superusers name upon booting into single-user and maintenance modes. |
| V-244523 | RHEL-08-010152 | medium | RHEL 8 operating systems must require authentication upon booting into emergency mode. |
| V-253265 | WN11-00-000050 | high | Local volumes must be formatted using NTFS. |
| V-253269 | WN11-00-000070 | high | Only accounts responsible for the administration of a system must have Administrator rights on the system. |
| V-253271 | WN11-00-000080 | medium | Only authorized user accounts must be allowed to create or run virtual machines on Windows 11 systems. |
| V-253274 | WN11-00-000095 | medium | Permissions for system files and directories must conform to minimum requirements. |
| V-253480 | WN11-UR-000010 | medium | The "Access this computer from the network" user right must only be assigned to the Administrators and Remote Desktop Users groups. |
| V-253482 | WN11-UR-000025 | medium | The "Allow log on locally" user right must only be assigned to the Administrators and Users groups. |
| V-253491 | WN11-UR-000070 | medium | The "Deny access to this computer from the network" user right on workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems. |
| V-253492 | WN11-UR-000075 | medium | The "Deny log on as a batch job" user right on domain-joined workstations must be configured to prevent access from highly privileged domain accounts. |
| V-253493 | WN11-UR-000080 | medium | The "Deny log on as a service" user right on Windows 11 domain-joined workstations must be configured to prevent access from highly privileged domain accounts. |
| V-253494 | WN11-UR-000085 | medium | The "Deny log on locally" user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems. |
| V-253495 | WN11-UR-000090 | medium | The "Deny log on through Remote Desktop Services" user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems. |
| V-254250 | WN22-00-000130 | high | Windows Server 2022 local volumes must use a format that supports NTFS attributes. |
| V-254251 | WN22-00-000140 | medium | Windows Server 2022 permissions for the system drive root directory (usually C:\) must conform to minimum requirements. |
| V-254252 | WN22-00-000150 | medium | Windows Server 2022 permissions for program file directories must conform to minimum requirements. |
| V-254253 | WN22-00-000160 | medium | Windows Server 2022 permissions for the Windows installation directory must conform to minimum requirements. |
| V-254255 | WN22-00-000180 | low | Windows Server 2022 nonadministrative accounts or groups must only have print permissions on printer shares. |
| V-254418 | WN22-DC-000340 | medium | Windows Server 2022 Access this computer from the network user right must only be assigned to the Administrators, Authenticated Users, and Enterprise Domain Controllers groups on domain controllers. |
| V-254420 | WN22-DC-000360 | medium | Windows Server 2022 Allow log on through Remote Desktop Services user right must only be assigned to the Administrators group on domain controllers. |
| V-254421 | WN22-DC-000370 | medium | Windows Server 2022 Deny access to this computer from the network user right on domain controllers must be configured to prevent unauthenticated access. |
| V-254422 | WN22-DC-000380 | medium | Windows Server 2022 Deny log on as a batch job user right on domain controllers must be configured to prevent unauthenticated access. |
| V-254423 | WN22-DC-000390 | medium | Windows Server 2022 Deny log on as a service user right must be configured to include no accounts or groups (blank) on domain controllers. |
| V-254424 | WN22-DC-000400 | medium | Windows Server 2022 Deny log on locally user right on domain controllers must be configured to prevent unauthenticated access. |
| V-254434 | WN22-MS-000070 | medium | Windows Server 2022 Access this computer from the network user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and standalone or nondomain-joined systems. |
| V-254435 | WN22-MS-000080 | medium | Windows Server 2022 Deny access to this computer from the network user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and local accounts and from unauthenticated access on all systems. |
| V-254436 | WN22-MS-000090 | medium | Windows Server 2022 Deny log on as a batch job user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems. |
| V-254437 | WN22-MS-000100 | medium | Windows Server 2022 Deny log on as a service user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts. No other groups or accounts must be assigned this right. |
| V-254438 | WN22-MS-000110 | medium | Windows Server 2022 Deny log on locally user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems. |
| V-254493 | WN22-UR-000030 | medium | Windows Server 2022 Allow log on locally user right must only be assigned to the Administrators group. |
| V-257787 | RHEL-09-212010 | medium | RHEL 9 must require a boot loader superuser password. |
| V-257789 | RHEL-09-212020 | high | RHEL 9 must require a unique superusers name upon booting into single-user and maintenance modes. |
| V-257801 | RHEL-09-213030 | medium | RHEL 9 must enable kernel parameters to enforce discretionary access control on hardlinks. |
| V-257802 | RHEL-09-213035 | medium | RHEL 9 must enable kernel parameters to enforce discretionary access control on symlinks. |
| V-258088 | RHEL-09-432035 | medium | RHEL 9 must restrict the use of the "su" command. |
| V-258128 | RHEL-09-611195 | medium | RHEL 9 must require authentication to access emergency mode. |
| V-258129 | RHEL-09-611200 | medium | RHEL 9 must require authentication to access single-user mode. |
| V-271426 | WN22-DC-000405 | medium | Windows Server 2022 must be configured for certificate-based authentication for domain controllers. |
| V-271427 | WN22-DC-000406 | medium | Windows Server 2022 must be configured for name-based strong mappings for certificates. |
| V-271428 | WN19-DC-000391 | medium | Windows Server 2019 must be configured for certificate-based authentication for domain controllers. |
| V-271429 | WN19-DC-000401 | medium | Windows Server 2019 must be configured for named-based strong mappings for certificates. |
| V-274882 | CNTR-K8-001162 | high | Kubernetes Secrets must be encrypted at rest. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AC-3. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.