{
  "node_id": "cyber-nist-800-53-ac2",
  "title": "Account Management (NIST SP 800-53 AC-2)",
  "domain": "Cybersecurity",
  "version": "1.1.0",
  "last_updated": "2026-04-09",
  "bluf": "The Account Management control establishes a comprehensive framework, consistent with NIST Special Publication 800-53 AC-2, for managing the full lifecycle of information system accounts. This governance is essential for satisfying the identity management and access rights principles of ISO/IEC 27001, supporting the security of processing measures under GDPR Article 32, and meeting the logical access security criteria specified by SOC 2 CC6.3 and PCI DSS Requirement 8.1. System configuration mandates that all account provisioning actions must `require_manager_approval` and strictly `enforce_least_privilege`. To maintain operational integrity, the platform will `audit_account_creation_and_modification` activities, `alert_on_privileged_role_assignment`, and `enforce_separation_of_duties`. Access rights undergo a `periodic_review_interval_days` of every 90 days, while dormant accounts are subject to `auto_disable_inactive_days` after 35 days of inactivity. Temporary accounts are constrained by a `max_temporary_account_validity_hours` of 72 hours. Deprovisioning procedures are executed swiftly, with a mandate to `terminate_access_on_departure_hours` within 24 hours of notification and to `auto_remove_orphaned_accounts` systematically. Security is hardened by limiting `max_failed_login_attempts` to 3 and ensuring administrative functions `require_mfa_for_account_management`, thereby creating a robust, auditable system for managing identities and permissions.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "ai_overlay_2026",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "fips-199-security-categorization",
    "fips-200-minimum-security-requirements",
    "nist-sp-800-53-r5",
    "nist-sp-800-63b-authentication",
    "nist-800-53-ia2",
    "cis-controls-v8"
  ],
  "primary_citations_count": 7
}