World Of Taxonomy
ac_3LeafLevel 2

AC-3 - Access Enforcement

AC-3 requires the information system to enforce approved authorizations for logical and physical access, ensuring that only authorized users, processes, or devices can perform specific actions. It mandates the implementation of access enforcement mechanisms-such as role-based controls, rule-based filters, or policies-that restrict access based on the organization's access control policy. The control also calls for periodic review and updates of these mechanisms to address changes in authorizations or system configurations.

GET/api/v1/systems/reg_nist_800_53/nodes/ac_3
Manual TranscriptionPublic DomainSource

Cross-system equivalences0

No cross-system equivalences mapped for this node.