STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

AC-2 (11)

Access ControlRev 5system

Account Management

Baselines:High

Control Statement

Enforce [Assignment: circumstances and/or usage conditions] for [Assignment: system accounts].

Supplemental Guidance

Specifying and enforcing usage conditions helps to enforce the principle of least privilege, increase user accountability, and enable effective account monitoring. Account monitoring includes alerts generated if the account is used in violation of organizational parameters. Organizations can describe specific conditions or circumstances under which system accounts can be used, such as by restricting usage to certain days of the week, time of day, or specific durations of time.

CCI Identifiers (3)

CCI-002143Defines the circumstances and/or usage conditions that are to be enforced for organization-defined information system accounts.CCI-002144Defines the system accounts that are to be subject to the enforcement of organization-defined circumstances and/or usage conditions.CCI-002145Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts.

Linked STIG Checks (15)

Across 13 STIGs. Click to expand.