AC-1—Policy and Procedures
>Control Description
Develop, document, and disseminate to: organizational personnel with access control responsibilities (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
Agency-level access control policy that:
Procedures to facilitate the implementation of the access control policy and the associated access controls;
Designate an individual with security responsibilities to manage the development, documentation, and dissemination of the access control policy and procedures; and
Review and update the current access control:
Policy annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI; and
Procedures annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.