Control library
Access Control · AC-2
Account Management
- Plain English
- You must know every account on the system, who approved it, and prove you review them on a schedule.
- Why this matters
- Orphaned and over-privileged accounts are the most common initial access path in federal breach reports.
- Common failure
- Accounts created ad hoc via ticket with no documented approver and no recurring recertification.
- Required SSP language
- The organization defines account types, assigns account managers, requires approvals for account creation, and reviews accounts quarterly.
Indicators
Documented approval workflowQuarterly account reviewAutomated disablement of inactive accounts
Assessment_Working
Implementation evidence
ctaf-rules-v1.0 (workbook parity)
Decision engine preview
Status
Not Assessed
Risk
Not Assessed
POA&M needed
No
Rule trace: No assessment row exists for this control.
Known limitation (Handoff §5.1): keyword precedence reproduces the workbook exactly, so phrasing like "no gaps identified" classifies as Not Met. Parity is intentional pending an explicit customer decision.