NIST AC-2 account management: a short lesson
ILM Reference editors · Published 2026-01-13 · 2 minute read
TRACK: CONTROLS AND STANDARDS · LESSON 4 OF 11
AC-2 is the account management control in NIST SP 800-53 Rev. 5. Its twelve items cover the whole identity lifecycle, from defining allowed account types to disabling accounts when people leave. Read it as a checklist grouped by stage: define, create, change, review and remove.
Where does AC-2 come from?
NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations, was published in September 2020 and updated on 10 December 2020; NIST issued minor release 5.2.0 of the catalog on 27 August 2025. It is mandatory for US federal information systems, and many private organizations map their controls to it.
What do the twelve items ask for, stage by stage?
| Stage | Item | What it asks for |
|---|---|---|
| Define | (a) | Define and document allowed and prohibited account types |
| Define | (b) | Assign account managers |
| Define | (c) | Set prerequisites and criteria for group and role membership |
| Define | (d) | Specify authorized users, group and role membership, and access privileges |
| Create | (e) | Require approval for requests to create accounts |
| Create, change, remove | (f) | Create, enable, modify, disable and remove accounts in line with policy |
| Review | (g) | Monitor the use of accounts |
| Change, remove | (h) | Notify account managers when accounts are no longer needed, or users are terminated or transferred |
| Create, change | (i) | Authorize access based on valid authorization, intended use and other attributes |
| Review | (j) | Review accounts for compliance at a defined frequency |
| Remove | (k) | Change shared or group authenticators when members leave the group |
| Change, remove | (l) | Align account management with personnel termination and transfer processes |
What does AC-2(3) add?
Control enhancement AC-2(3), Disable Accounts, asks organizations to disable accounts within a period they define when the accounts have expired, are no longer associated with a user or individual, violate policy, or have been inactive for a defined period. The second condition is the formal description of an orphan account.
Item (j) is where access certifications come in; see access certification. Items (h) and (l) are where the joiner-mover-leaver process meets HR.
Sources
Reviewed Sep 2026
AC-2 control text, catalog mirror: verify against the NIST catalog.
Next lesson: RBAC, ABAC and least privilege
Two ways to decide who gets access, and the principle both are meant to serve.