REGISTER REVISED SEPTEMBER 2026

NIST AC-2 account management: a short lesson

ILM Reference editors · Published 2026-01-13 · 2 minute read

TRACK: CONTROLS AND STANDARDS · LESSON 4 OF 11

SUMMARYREV. 2026-09

AC-2 is the account management control in NIST SP 800-53 Rev. 5. Its twelve items cover the whole identity lifecycle, from defining allowed account types to disabling accounts when people leave. Read it as a checklist grouped by stage: define, create, change, review and remove.

§ 01

Where does AC-2 come from?

NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations, was published in September 2020 and updated on 10 December 2020; NIST issued minor release 5.2.0 of the catalog on 27 August 2025. It is mandatory for US federal information systems, and many private organizations map their controls to it.

§ 02

What do the twelve items ask for, stage by stage?

AC-2 items (a) to (l), summarized from the control text and grouped by lifecycle stage.
StageItemWhat it asks for
Define(a)Define and document allowed and prohibited account types
Define(b)Assign account managers
Define(c)Set prerequisites and criteria for group and role membership
Define(d)Specify authorized users, group and role membership, and access privileges
Create(e)Require approval for requests to create accounts
Create, change, remove(f)Create, enable, modify, disable and remove accounts in line with policy
Review(g)Monitor the use of accounts
Change, remove(h)Notify account managers when accounts are no longer needed, or users are terminated or transferred
Create, change(i)Authorize access based on valid authorization, intended use and other attributes
Review(j)Review accounts for compliance at a defined frequency
Remove(k)Change shared or group authenticators when members leave the group
Change, remove(l)Align account management with personnel termination and transfer processes
§ 03

What does AC-2(3) add?

Control enhancement AC-2(3), Disable Accounts, asks organizations to disable accounts within a period they define when the accounts have expired, are no longer associated with a user or individual, violate policy, or have been inactive for a defined period. The second condition is the formal description of an orphan account.

Item (j) is where access certifications come in; see access certification. Items (h) and (l) are where the joiner-mover-leaver process meets HR.

Sources

Reviewed Sep 2026

AC-2 control text, catalog mirror: verify against the NIST catalog.

NEXT LESSONREV. 2026-09

Next lesson: RBAC, ABAC and least privilege

Two ways to decide who gets access, and the principle both are meant to serve.

Related

GUIDEREV. 2026-09
LESSONREV. 2026-09
TERMREV. 2026-09