PlumbTrackLive demoGRC Risk System

← control library

Information Sharing AC-21

Access Control · Moderate baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds AC-21 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Access Control family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

AC-21 (Information Sharing) is about helping people make good decisions when they hand information to an outside partner — another team, a vendor, an agency, or another system. Before anything moves, the person sharing it needs to know two things: is this partner actually authorized to receive it, and does the way they will use it match the restrictions on that information? The control has two parts — give users a way to check that a partner's access authorizations match the information's access and use restrictions, and provide help (a defined automated mechanism or manual process, not just memory) to support those sharing decisions. It is an Access Control that appears in the Moderate baseline.

What good looks like

Framework mapping

How to move it toward Implemented