Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family AC

AC-5Separation of Duties

Identify and document {{ insert: param, ac-05_odp }} ; and Define system access authorizations to support separation of duties.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (165)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control4,832Defining authorizations to support separation of duties strengthens overall access control by preventing unauthorized combinations of actions within a single account.
CWE-269Improper Privilege Management2,907By mandating division of duties across roles, the control enforces proper privilege management and prevents a single entity from controlling an entire sensitive process.
CWE-285Improper Authorization1,230The control requires authorizations to be structured around separated duties, mitigating improper authorization that would otherwise allow one user to perform conflicting operations.
CWE-266Incorrect Privilege Assignment826The control requires explicit definition of separated access authorizations, making incorrect privilege assignments that bundle conflicting duties harder to implement.
CWE-250Execution with Unnecessary Privileges305Separation of duties prevents any single user from holding all privileges needed to complete a critical task, directly reducing execution with unnecessary privileges.
CWE-272Least Privilege Violation25Separation of duties is a direct mechanism to enforce least privilege by ensuring no individual receives more access than required for their isolated responsibilities.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2026-297892.09.90.0006partial
CVE-2026-276681.88.80.0004good
CVE-2026-290731.88.80.0006partial
CVE-2026-309441.88.80.0005partial
CVE-2026-264161.88.80.0004good
CVE-2026-258591.88.80.0002partial
CVE-2026-345871.68.10.0003partial
CVE-2026-405911.47.10.0003partial
CVE-2025-08491.36.30.0003partial
CVE-2025-256160.94.30.0057partial

Other controls in family AC

AC-1 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-17 AC-18 AC-19 AC-2 AC-20 AC-21 AC-22 AC-23 AC-24 AC-25 AC-3 AC-4 AC-6 AC-7 AC-8 AC-9