id: "AC-02(13)" title: "Disable Accounts for High-risk Individuals" family: "AC" family_name: "Access Control" sort_id: "ac-02.13" priority: "P1" implementation_level: "organization" parent: "AC-02" enhancement: True


Statement

Disable accounts of individuals within {{ insert: param, ac-02.13_odp.01 }} of discovery of {{ insert: param, ac-02.13_odp.02 }}.

Guidance

Users who pose a significant security and/or privacy risk include individuals for whom reliable evidence indicates either the intention to use authorized access to systems to cause harm or through whom adversaries will cause harm. Such harm includes adverse impacts to organizational operations, organizational assets, individuals, other organizations, or the Nation. Close coordination among system administrators, legal staff, human resource managers, and authorizing officials is essential when disabling system accounts for high-risk individuals.

Assessment Objective

accounts of individuals are disabled within {{ insert: param, ac-02.13_odp.01 }} of discovery of {{ insert: param, ac-02.13_odp.02 }}.

Access control policy

procedures addressing account management

system design documentation

system configuration settings and associated documentation

system-generated list of disabled accounts

list of user activities posing significant organizational risk

system audit records

system security plan

other relevant documents or records

Organizational personnel with account management responsibilities

system/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing account management functions