id: "AC-03(10)" title: "Audited Override of Access Control Mechanisms" family: "AC" family_name: "Access Control" sort_id: "ac-03.10" priority: "P1" implementation_level: "organization" parent: "AC-03" enhancement: True


Statement

Employ an audited override of automated access control mechanisms under {{ insert: param, ac-03.10_odp.01 }} by {{ insert: param, ac-03.10_odp.02 }}.

Guidance

In certain situations, such as when there is a threat to human life or an event that threatens the organization’s ability to carry out critical missions or business functions, an override capability for access control mechanisms may be needed. Override conditions are defined by organizations and used only in those limited circumstances. Audit events are defined in AU-2 . Audit records are generated in AU-12.

Assessment Objective

an audited override of automated access control mechanisms is employed under {{ insert: param, ac-03.10_odp.01 }} by {{ insert: param, ac-03.10_odp.02 }}.

Access control policy

procedures addressing access enforcement

system design documentation

system configuration settings and associated documentation

conditions for employing audited override of automated access control mechanisms

system audit records

system security plan

other relevant documents or records

Organizational personnel with access enforcement responsibilities

system/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing access enforcement functions