PlumbTrackLive demoGRC Risk System

← control library

Permitted Actions Without Identification or Authentication AC-14

Access Control · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds AC-14 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Access Control family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

AC-14 (Permitted Actions Without Identification or Authentication) is about deciding, on purpose, the short list of things a person can do on the system before they prove who they are. Identification means claiming an identity (a username); authentication means proving it (a password or key). The control asks two plain questions: which actions, if any, are allowed with no login — and where is that written down, with a reason? On a hardened system the honest answer is often ‘none,’ and AC-14 is the place you say so. It sits in the Low baseline.

What good looks like

Framework mapping

How to move it toward Implemented