Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family AC

AC-3Access Enforcement

Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (7)

ATT&CK techniques this control mitigates (279)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization8,680Requiring enforcement of authorizations ensures checks are performed rather than omitted for resources.
CWE-284Improper Access Control4,832Enforcing approved authorizations directly implements access control policies to block unauthorized access.
CWE-863Incorrect Authorization3,234Mandating policy-based enforcement reduces the chance of incorrect authorization logic being used.
CWE-639Authorization Bypass Through User-Controlled Key1,837Consistent enforcement of approved authorizations makes bypassing via user-controlled keys ineffective.
CWE-285Improper Authorization1,230The control requires checking and applying authorization decisions per policy, preventing improper authorization.
CWE-425Direct Request ('Forced Browsing')255Enforcing access for all logical requests prevents unauthorized direct access to protected resources.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-12480 KEV8.59.10.7832good
CVE-2025-6205 KEV8.59.10.7772good
CVE-2025-133156.99.80.8288good
CVE-2024-463106.89.10.8300good
CVE-2024-57968 KEV6.69.90.4366good
CVE-2015-101436.09.80.6745good
CVE-2024-122525.99.80.6649good
CVE-2012-100305.69.80.6098good
CVE-2025-24989 KEV5.58.20.3162good
CVE-2015-101405.28.80.5710good
CVE-2026-271804.99.80.4880good
CVE-2026-285154.48.80.4425good
CVE-2024-570494.09.80.3460good
CVE-2025-48572 KEV3.67.80.0021good
CVE-2024-125423.58.60.3039good
CVE-2024-559633.56.50.3723good
CVE-2025-663013.59.60.2622good
CVE-2026-20133 KEV3.46.50.0127good
CVE-2025-40602 KEV3.36.60.0041good
CVE-2026-20253.27.50.2799good
CVE-2025-298143.19.30.2086good
CVE-2023-471792.98.80.1915good
CVE-2025-118332.99.80.1525good
CVE-2026-318162.89.10.1586good
CVE-2024-123652.88.50.1826good

Other controls in family AC

AC-1 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-17 AC-18 AC-19 AC-2 AC-20 AC-21 AC-22 AC-23 AC-24 AC-25 AC-4 AC-5 AC-6 AC-7 AC-8 AC-9