Documents how the organization controls who can access the system, what they can do once authenticated, and how that access is reviewed and revoked. Covers the controls of the AC family in NIST SP 800-53 r5 and aligns with NIST SP 800-63 (Digital Identity Guidelines) and NIST SP 800-162 (ABAC).
Public site — unclassified data only.
Do not enter classified, CUI, or other sensitive non-public information into this plan. Use placeholders for sensitive content and complete those fields on an authorized system within the appropriate enclave.