Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family PS

PS-9Position Descriptions

Incorporate security and privacy roles and responsibilities into organizational position descriptions.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control4,832Clear role definitions in position descriptions are a prerequisite for implementing and enforcing proper access control decisions.
CWE-269Improper Privilege Management2,907Documenting security and privacy duties per position provides the foundation for consistent and correct privilege management across the organization.
CWE-732Incorrect Permission Assignment for Critical Resource1,824Security responsibilities documented in job descriptions guide correct initial and ongoing permission assignments for critical resources.
CWE-285Improper Authorization1,230Explicitly stated responsibilities per position improve the accuracy and consistency of authorization decisions tied to those roles.
CWE-250Execution with Unnecessary Privileges305Position descriptions that explicitly define security responsibilities directly support assignment of only the privileges needed for a role, reducing execution with unnecessary privileges.
CWE-272Least Privilege Violation25Incorporating least-privilege expectations into every position description makes violations of the principle harder to occur by default.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family PS

PS-1 PS-2 PS-3 PS-4 PS-5 PS-6 PS-7 PS-8