PlumbTrackLive demoGRC Risk System

← control library

Policy and Procedures AC-1

Access Control · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds AC-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Access Control family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

AC-1 (Policy and Procedures) is the governance control at the top of the Access Control family — every family has a ‘-1’. Unlike AC-2 onward (which harden technical things), AC-1 requires the written policy and procedures for how the organization does access control, a named owner, and a review cadence to keep them current. It is the foundation the technical AC controls rest on, and it carries from the Low baseline up.

What good looks like

Framework mapping

How to move it toward Implemented