STIGhub
STIGs
RMF Controls
Compare
← All Controls
AC-3 (4)
Access Control
Rev 3
Access Enforcement
CCI Identifiers (14)
CCI-000214
The organization establishes a Discretionary Access Control (DAC) policy that limits propagation of access rights.
CCI-000215
The organization establishes a Discretionary Access Control (DAC) policy that includes or excludes access to the granularity of a single user.
CCI-001362
The information system enforces a Discretionary Access Control (DAC) policy that allows users to specify and control sharing by named individuals or groups of individuals, or by both.
CCI-001363
The organization establishes a Discretionary Access Control (DAC) policy that allows users to specify and control sharing by named individuals or groups of individuals, or by both.
CCI-001693
The information system enforces a Discretionary Access Control (DAC) policy that limits propagation of access rights.
CCI-001694
The information system enforces a Discretionary Access Control (DAC) policy that includes or excludes access to the granularity of a single user.
CCI-002163
Defines the discretionary access control policies the information system is to enforce over subjects and objects.
CCI-002164
Enforce organization-defined discretionary access control policy that over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information can do one or more of the following: pass the information to any other subjects or objects; grant its privileges to other subjects; change security attributes on subjects, objects, the system, or the system's components; choose the security attributes to be associated with newly created or revised objects; and/or change the rules governing access control.
CCI-002165
Enforce organization-defined discretionary access control policies over defined subjects and objects.
CCI-003638
Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can pass the information to any other subjects or objects.
CCI-003639
Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can grant its privileges to other subjects.
CCI-003640
Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can change security attributes on subjects, objects, the system, or the system's components.
CCI-003641
Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can choose the security attributes to be associated with newly created or revised objects.
CCI-003642
Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can change the rules governing access control.
Linked STIG Checks (157)
Across 64 STIGs. Click to expand.
▶
Amazon Linux 2023 Security Technical Implementation Guide
4 checks
▶
Application Security and Development Security Technical Implementation Guide
1 check
▶
Arctic Wolf CylanceON-PREM Security Technical Implementation Guide
1 check
▶
Axonius Federal Systems Ax-OS Security Technical Implementation Guide
1 check
▶
Canonical Ubuntu 18.04 LTS Security Technical Implementation Guide
1 check
▶
Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide
1 check
▶
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
1 check
▶
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
1 check
▶
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
1 check
▶
Crunchy Data Postgres 16 Security Technical Implementation Guide
1 check
▶
Crunchy Data PostgreSQL Security Technical Implementation Guide
1 check
▶
Database Security Requirements Guide
1 check
▶
Docker Enterprise 2.x Linux/UNIX Security Technical Implementation Guide
2 checks
▶
Domain Name System (DNS) Security Requirements Guide
1 check
▶
EDB Postgres Advanced Server v11 on Windows Security Technical Implementation Guide
1 check
▶
EnterpriseDB Postgres Advanced Server (EPAS) Security Technical Implementation Guide
1 check
▶
General Purpose Operating System Security Requirements Guide
3 checks
▶
HP FlexFabric Switch NDM Security Technical Implementation Guide
1 check
▶
IBM AIX 7.x Security Technical Implementation Guide
4 checks
▶
IBM Aspera Platform 4.2 Security Technical Implementation Guide
12 checks
▶
IBM DataPower Network Device Management Security Technical Implementation Guide
1 check
▶
Mainframe Product Security Requirements Guide
1 check
▶
MariaDB Enterprise 10.x Security Technical Implementation Guide
1 check
▶
Microsoft Azure SQL Database Security Technical Implementation Guide
1 check
▶
Microsoft Azure SQL Managed Instance Security Technical Implementation Guide
1 check
▶
Microsoft SQL Server 2022 Database Security Technical Implementation Guide
1 check
▶
Microsoft Windows 10 Security Technical Implementation Guide
1 check
▶
Microsoft Windows 11 Security Technical Implementation Guide
3 checks
▶
Microsoft Windows Server 2016 Security Technical Implementation Guide
3 checks
▶
Microsoft Windows Server 2019 Security Technical Implementation Guide
3 checks
▶
Microsoft Windows Server 2022 Security Technical Implementation Guide
3 checks
▶
Microsoft Windows Server 2025 Security Technical Implementation Guide
3 checks
▶
MongoDB Enterprise Advanced 3.x Security Technical Implementation Guide
1 check
▶
MongoDB Enterprise Advanced 4.x Security Technical Implementation Guide
1 check
▶
MongoDB Enterprise Advanced 7.x Security Technical Implementation Guide
1 check
▶
MongoDB Enterprise Advanced 8.x Security Technical Implementation Guide
1 check
▶
MS SQL Server 2016 Database Security Technical Implementation Guide
1 check
▶
Network Device Management Security Requirements Guide
1 check
▶
Nutanix Acropolis GPOS Security Technical Implementation Guide
3 checks
▶
Nutanix AOS 5.20.x OS Security Technical Implementation Guide
1 check
▶
Oracle Database 11.2g Security Technical Implementation Guide
3 checks
▶
Oracle Database 12c Security Technical Implementation Guide
3 checks
▶
Oracle Linux 7 Security Technical Implementation Guide
6 checks
▶
Oracle Linux 8 Security Technical Implementation Guide
2 checks
▶
Oracle Linux 9 Security Technical Implementation Guide
3 checks
▶
Oracle MySQL 8.0 Security Technical Implementation Guide
1 check
▶
PostgreSQL 9.x Security Technical Implementation Guide
1 check
▶
Red Hat Enterprise Linux 10 Security Technical Implementation Guide
4 checks
▶
Red Hat Enterprise Linux 7 Security Technical Implementation Guide
9 checks
▶
Red Hat Enterprise Linux 8 Security Technical Implementation Guide
2 checks
▶
Red Hat Enterprise Linux 9 Security Technical Implementation Guide
3 checks
▶
Redis Enterprise 6.x Security Technical Implementation Guide
2 checks
▶
SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation Guide
1 check
▶
SUSE Linux Enterprise Server 12 Security Technical Implementation Guide
3 checks
▶
Tanium 7.0 Security Technical Implementation Guide
7 checks
▶
Tanium 7.3 Security Technical Implementation Guide
7 checks
▶
Tanium 7.x Application on TanOS Security Technical Implementation Guide
3 checks
▶
Tanium 7.x Security Technical Implementation Guide
7 checks
▶
Tri-Lab Operating System Stack (TOSS) 4 Security Technical Implementation Guide
2 checks
▶
Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide
2 checks
▶
Virtual Machine Manager Security Requirements Guide
4 checks
▶
Windows Server 2016 Security Technical Implementation Guide
6 checks
▶
Windows Server 2019 Security Technical Implementation Guide
3 checks
▶
Xylok Security Suite 20.x Security Technical Implementation Guide
1 check