id: "AC-03(08)" title: "Revocation of Access Authorizations" family: "AC" family_name: "Access Control" sort_id: "ac-03.08" priority: "P1" implementation_level: "system" parent: "AC-03" enhancement: True


Statement

Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on {{ insert: param, ac-03.08_odp }}.

Guidance

Revocation of access rules may differ based on the types of access revoked. For example, if a subject (i.e., user or process acting on behalf of a user) is removed from a group, access may not be revoked until the next time the object is opened or the next time the subject attempts to access the object. Revocation based on changes to security labels may take effect immediately. Organizations provide alternative approaches on how to make revocations immediate if systems cannot provide such capability and immediate revocation is necessary.

Assessment Objective: revocation of access authorizations is enforced, resulting from changes to the security attributes of subjects based on {{ insert: param, ac-03.08_odp }};

Assessment Objective: revocation of access authorizations is enforced resulting from changes to the security attributes of objects based on {{ insert: param, ac-03.08_odp }}.

Access control policy

procedures addressing access enforcement

system design documentation

system configuration settings and associated documentation

rules governing revocation of access authorizations, system audit records

system security plan

other relevant documents or records

Organizational personnel with access enforcement responsibilities

system/network administrators

organizational personnel with information security responsibilities

system developers

Mechanisms implementing access enforcement functions