Skip to content

AC-2: Account Management

An OSCAL Control

Statement

    • a.

      Define and document the types of accounts allowed and specifically prohibited for use within the system;

    • f.

      Create, enable, modify, disable, and remove accounts in accordance with ;

    • g.

      Monitor the use of accounts;

    • h.

      Notify account managers and within:

      • 1.

        when accounts are no longer required;

      • 2.

        when users are terminated or transferred; and

      • 3.

        when system usage or need-to-know changes for an individual;