id: "AC-03(10)" title: "Audited Override of Access Control Mechanisms" family: "AC" family_name: "Access Control" sort_id: "ac-03.10" priority: "P1" implementation_level: "organization" parent: "AC-03" enhancement: True
Statement
Employ an audited override of automated access control mechanisms under {{ insert: param, ac-03.10_odp.01 }} by {{ insert: param, ac-03.10_odp.02 }}.
Guidance
In certain situations, such as when there is a threat to human life or an event that threatens the organization’s ability to carry out critical missions or business functions, an override capability for access control mechanisms may be needed. Override conditions are defined by organizations and used only in those limited circumstances. Audit events are defined in AU-2 . Audit records are generated in AU-12.
Assessment Objective
an audited override of automated access control mechanisms is employed under {{ insert: param, ac-03.10_odp.01 }} by {{ insert: param, ac-03.10_odp.02 }}.
Access control policy
procedures addressing access enforcement
system design documentation
system configuration settings and associated documentation
conditions for employing audited override of automated access control mechanisms
system audit records
system security plan
other relevant documents or records
Organizational personnel with access enforcement responsibilities
system/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing access enforcement functions