Policy and Procedures AC-1
Access Control · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds AC-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Access Control family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
AC-1 (Policy and Procedures) is the governance control at the top of the Access Control family — every family has a ‘-1’. Unlike AC-2 onward (which harden technical things), AC-1 requires the written policy and procedures for how the organization does access control, a named owner, and a review cadence to keep them current. It is the foundation the technical AC controls rest on, and it carries from the Low baseline up.
What good looks like
- A documented access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination across units, and compliance — and is consistent with applicable laws, regulations, standards, and guidelines.
- Procedures that implement the policy: the how-to that turns it into day-to-day action (how access is requested, approved, granted, and revoked).
- A designated official who owns the policy and procedures — a named, accountable person, not ‘the team’.
- The policy and procedures are reviewed and updated on a defined frequency (for example, annually) and after events like a breach, a reorganization, or a new regulation.
- The policy is disseminated to the people who need it, so it is actually known and followed.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Organizational cybersecurity policy is established and communicated
- NIST CSF 2.0 — GV.PO-02 — Policy is reviewed, updated, and communicated to reflect changes
How to move it toward Implemented
- Write (or adopt) a one- to two-page Access Control Policy covering purpose, scope, roles, responsibilities, and compliance; get it approved and dated.
- Document the procedures that carry it out — how accounts are requested and approved, how access is granted and revoked, and how reviews run.
- Name an owner in the policy and set a review date (for example, review annually and after any major change).
- Attach the approved policy and procedures as hardening evidence on the asset, naming
AC-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.