id: "AC-02(11)" title: "Usage Conditions" family: "AC" family_name: "Access Control" sort_id: "ac-02.11" priority: "P1" implementation_level: "system" parent: "AC-02" enhancement: True
Statement
Enforce {{ insert: param, ac-02.11_odp.01 }} for {{ insert: param, ac-02.11_odp.02 }}.
Guidance
Specifying and enforcing usage conditions helps to enforce the principle of least privilege, increase user accountability, and enable effective account monitoring. Account monitoring includes alerts generated if the account is used in violation of organizational parameters. Organizations can describe specific conditions or circumstances under which system accounts can be used, such as by restricting usage to certain days of the week, time of day, or specific durations of time.
Assessment Objective
{{ insert: param, ac-02.11_odp.01 }} for {{ insert: param, ac-02.11_odp.02 }} are enforced.
Access control policy
procedures addressing account management
system design documentation
system configuration settings and associated documentation
system-generated list of system accounts and associated assignments of usage circumstances and/or usage conditions
system audit records
system security plan
other relevant documents or records
Organizational personnel with account management responsibilities
system/network administrators
organizational personnel with information security responsibilities
system developers
Mechanisms implementing account management functions