Under active development Content is continuously updated and improved · Last updated Feb 18, 2026, 2:55 AM UTC

AC-02(13)Account Management | Disable Accounts for High-risk Individuals

Moderate

>Control Description

Disable accounts of individuals within organization-defined time period of discovery of organization-defined significant risks.

>Discussion

Users who pose a significant security and/or privacy risk include individuals for whom reliable evidence indicates either the intention to use authorized access to systems to cause harm or through whom adversaries will cause harm. Such harm includes adverse impacts to organizational operations, organizational assets, individuals, other organizations, or the Nation. Close coordination among system administrators, legal staff, human resource managers, and authorizing officials is essential when disabling system accounts for high-risk individuals.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.