Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family AC

AC-22Publicly Accessible Content

Designate individuals authorized to make information publicly accessible; Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information; Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included; and Review the content on the publicly accessible system for nonpublic information {{ insert: param, ac-22_odp }} and remove such information, if discovered.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (8)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-200Exposure of Sensitive Information to an Unauthorized Actor11,000+Review and removal of nonpublic information from publicly accessible systems directly prevents exposure of sensitive data to unauthorized actors.
CWE-284Improper Access Control6,900+Designating authorized individuals and mandating pre/post-publication reviews enforces access controls on who can publish content publicly.
CWE-285Improper Authorization1,500+Authorization checks via training and content reviews ensure only approved information is released to public systems.
CWE-668Exposure of Resource to Wrong Sphere800+The control ensures information resources are not exposed to the incorrect (public) sphere through review and authorization.
CWE-552Files or Directories Accessible to External Parties500+Controls on authorized publication limit files and directories with nonpublic data from becoming accessible to external parties.
CWE-497Exposure of Sensitive System Information to an Unauthorized Control Sphere300+Ongoing reviews detect and remove sensitive system information before it reaches publicly accessible systems.
CWE-359Exposure of Private Personal Information to an Unauthorized Actor200+Preventing nonpublic personal information from public posting reduces unauthorized exposure of private personal data.
CWE-538Insertion of Sensitive Information into Externally-Accessible File or Directory98Pre- and post-publication reviews prevent insertion of sensitive information into externally-accessible public locations.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family AC

AC-1 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-17 AC-18 AC-19 AC-2 AC-20 AC-21 AC-23 AC-24 AC-25 AC-3 AC-4 AC-5 AC-6 AC-7 AC-8 AC-9