NIST 800-53 r5 · Controls catalogue · Family AC
AC-16Security and Privacy Attributes
Provide the means to associate {{ insert: param, ac-16_prm_1 }} with {{ insert: param, ac-16_prm_2 }} for information in storage, in process, and/or in transmission; Ensure that the attribute associations are made and retained with the information; Establish the following permitted security and privacy attributes from the attributes defined in [AC-16a](#ac-16_smt.a) for {{ insert: param, ac-16_prm_3 }}: {{ insert: param, ac-16_prm_4 }}; Determine the following permitted attribute values or ranges for each of the established attributes: {{ insert: param, ac-16_odp.09 }}; Audit changes to attributes; and Review {{ insert: param, ac-16_prm_6 }} for applicability {{ insert: param, ac-16_prm_7 }}.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (57)
- T1003 OS Credential Dumping Credential Access
- T1003.003 NTDS Credential Access
- T1005 Data from Local System Collection
- T1020.001 Traffic Duplication Exfiltration
- T1025 Data from Removable Media Collection
- T1040 Network Sniffing Credential Access, Discovery
- T1041 Exfiltration Over C2 Channel Exfiltration
- T1048 Exfiltration Over Alternative Protocol Exfiltration
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol Exfiltration
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol Exfiltration
- T1052 Exfiltration Over Physical Medium Exfiltration
- T1052.001 Exfiltration over USB Exfiltration
- T1070 Indicator Removal Stealth
- T1070.008 Clear Mailbox Data Stealth
- T1114 Email Collection Collection
- T1114.001 Local Email Collection Collection
- T1114.002 Remote Email Collection Collection
- T1114.003 Email Forwarding Rule Collection
- T1119 Automated Collection Collection
- T1213 Data from Information Repositories Collection
- T1213.001 Confluence Collection
- T1213.002 Sharepoint Collection
- T1213.004 Customer Relationship Management Software Collection
- T1213.005 Messaging Applications Collection
- T1222 File and Directory Permissions Modification Defense Impairment
- T1222.001 Windows Permissions Defense Impairment
- T1222.002 Linux and Mac Permissions Defense Impairment
- T1505 Server Software Component Persistence
- T1505.002 Transport Agent Persistence
- T1530 Data from Cloud Storage Collection
- T1537 Transfer Data to Cloud Account Exfiltration
- T1547.007 Re-opened Applications Persistence, Privilege Escalation
- T1548 Abuse Elevation Control Mechanism Privilege Escalation
- T1548.003 Sudo and Sudo Caching Privilege Escalation
- T1548.006 TCC Manipulation Privilege Escalation
- T1550.001 Application Access Token Lateral Movement
- T1552 Unsecured Credentials Credential Access
- T1552.004 Private Keys Credential Access
- T1552.005 Cloud Instance Metadata API Credential Access
- T1556.009 Conditional Access Policies Defense Impairment, Persistence, Credential Access
- T1557 Adversary-in-the-Middle Credential Access, Collection
- T1557.002 ARP Cache Poisoning Credential Access, Collection
- T1558 Steal or Forge Kerberos Tickets Credential Access
- T1558.002 Silver Ticket Credential Access
- T1558.003 Kerberoasting Credential Access
- T1558.004 AS-REP Roasting Credential Access
- T1564.004 NTFS File Attributes Stealth
- T1565 Data Manipulation Impact
- T1565.001 Stored Data Manipulation Impact
- T1565.002 Transmitted Data Manipulation Impact
Weaknesses this control addresses (8)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 11,000+ | Proper attribute retention and permitted-value enforcement limits unauthorized actors from accessing sensitive information lacking correct labels. |
CWE-862 | Missing Authorization | 10,200+ | Requiring attribute association with information prevents authorization from being performed without necessary security or privacy context. |
CWE-284 | Improper Access Control | 6,900+ | Associating and retaining security attributes with data directly supports enforcement of access control decisions across storage, processing, and transmission. |
CWE-863 | Incorrect Authorization | 3,900+ | Defining permitted attribute values and auditing modifications reduces the chance of incorrect authorization outcomes due to tampered or missing labels. |
CWE-732 | Incorrect Permission Assignment for Critical Resource | 1,900+ | Attribute management for resources provides a mechanism to assign and maintain correct permissions based on security labels. |
CWE-285 | Improper Authorization | 1,500+ | Establishing permitted attributes and values, plus auditing changes, ensures authorization decisions are based on correctly managed policy data. |
CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor | 200+ | Privacy-specific attributes and their controlled association directly reduce exposure of private personal information through missing or incorrect labeling. |
CWE-1220 | Insufficient Granularity of Access Control | 100+ | Use of granular security and privacy attributes enables finer access control than coarse permission models alone. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-47269 UPD | 8.2 | 8.3 | 0.4296 | good |
CVE-2024-54465 UPD | 7.5 | 9.8 | 0.0088 | good |
CVE-2024-56973 UPD | 7.5 | 9.8 | 0.0090 | good |
CVE-2026-39906 UPD | 7.5 | 10.0 | 0.0069 | good |
CVE-2024-36532 UPD | 7.4 | 10.0 | 0.0045 | good |
CVE-2024-41644 | 7.4 | 9.8 | 0.0068 | good |
CVE-2024-41645 | 7.4 | 9.8 | 0.0068 | good |
CVE-2024-41646 | 7.4 | 9.8 | 0.0068 | good |
CVE-2024-41649 | 7.4 | 9.8 | 0.0068 | good |
CVE-2024-55507 UPD | 7.4 | 9.8 | 0.0061 | good |
CVE-2024-46622 UPD | 7.4 | 9.8 | 0.0059 | good |
CVE-2024-41648 | 7.3 | 9.8 | 0.0048 | good |
CVE-2024-41650 | 7.3 | 9.8 | 0.0047 | good |
CVE-2024-46310 UPD | 7.3 | 9.1 | 0.0248 | good |
CVE-2025-62718 UPD | 7.3 | 9.9 | 0.0119 | good |
CVE-2026-42933 | 7.3 | 10.0 | 0.0029 | good |
CVE-2025-64123 UPD | 7.2 | 9.8 | 0.0029 | good |
CVE-2024-54879 UPD | 7.0 | 9.1 | 0.0093 | good |
CVE-2024-54880 UPD | 7.0 | 9.1 | 0.0090 | good |
CVE-2025-68667 UPD | 7.0 | 9.9 | 0.0059 | good |
CVE-2025-64125 UPD | 7.0 | 9.4 | 0.0023 | good |
CVE-2026-24471 UPD | 7.0 | 9.3 | 0.0031 | good |
CVE-2026-23556 | 7.0 | 9.4 | 0.0014 | good |
CVE-2026-15183 | 7.0 | 9.2 | 0.0021 | good |
CVE-2025-43698 UPD | 6.9 | 9.1 | 0.0046 | good |