id: "AC-02(13)" title: "Disable Accounts for High-risk Individuals" family: "AC" family_name: "Access Control" sort_id: "ac-02.13" priority: "P1" implementation_level: "organization" parent: "AC-02" enhancement: True
Statement
Disable accounts of individuals within {{ insert: param, ac-02.13_odp.01 }} of discovery of {{ insert: param, ac-02.13_odp.02 }}.
Guidance
Users who pose a significant security and/or privacy risk include individuals for whom reliable evidence indicates either the intention to use authorized access to systems to cause harm or through whom adversaries will cause harm. Such harm includes adverse impacts to organizational operations, organizational assets, individuals, other organizations, or the Nation. Close coordination among system administrators, legal staff, human resource managers, and authorizing officials is essential when disabling system accounts for high-risk individuals.
Assessment Objective
accounts of individuals are disabled within {{ insert: param, ac-02.13_odp.01 }} of discovery of {{ insert: param, ac-02.13_odp.02 }}.
Access control policy
procedures addressing account management
system design documentation
system configuration settings and associated documentation
system-generated list of disabled accounts
list of user activities posing significant organizational risk
system audit records
system security plan
other relevant documents or records
Organizational personnel with account management responsibilities
system/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing account management functions