AC-02.3 ยท Disable Accounts

Control Description

Disable accounts within {{ insert: param, ac-02.03_odp.01 }} when the accounts:

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
system
Enhancement
Control Statement
The control requirements

Disable accounts within {{ insert: param, ac-02.03_odp.01 }} when the accounts:

(a) Have expired;

(b) Are no longer associated with a user or individual;

(c) Are in violation of organizational policy; or

(d) Have been inactive for {{ insert: param, ac-02.03_odp.02 }}.

Supplemental Guidance

Disabling expired, inactive, or otherwise anomalous accounts supports the concepts of least privilege and least functionality which reduce the attack surface of the system.