id: "AC-03(08)" title: "Revocation of Access Authorizations" family: "AC" family_name: "Access Control" sort_id: "ac-03.08" priority: "P1" implementation_level: "system" parent: "AC-03" enhancement: True
Statement
Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on {{ insert: param, ac-03.08_odp }}.
Guidance
Revocation of access rules may differ based on the types of access revoked. For example, if a subject (i.e., user or process acting on behalf of a user) is removed from a group, access may not be revoked until the next time the object is opened or the next time the subject attempts to access the object. Revocation based on changes to security labels may take effect immediately. Organizations provide alternative approaches on how to make revocations immediate if systems cannot provide such capability and immediate revocation is necessary.
Assessment Objective: revocation of access authorizations is enforced, resulting from changes to the security attributes of subjects based on {{ insert: param, ac-03.08_odp }};
Assessment Objective: revocation of access authorizations is enforced resulting from changes to the security attributes of objects based on {{ insert: param, ac-03.08_odp }}.
Access control policy
procedures addressing access enforcement
system design documentation
system configuration settings and associated documentation
rules governing revocation of access authorizations, system audit records
system security plan
other relevant documents or records
Organizational personnel with access enforcement responsibilities
system/network administrators
organizational personnel with information security responsibilities
system developers
Mechanisms implementing access enforcement functions