Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family AC

AC-3Access Enforcement

Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

Last updated: 19 May 2026 14:18 UTC

Implementations targeting this control (32)

ATT&CK techniques this control mitigates (279)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization8,796Requiring enforcement of authorizations ensures checks are performed rather than omitted for resources.
CWE-284Improper Access Control4,905Enforcing approved authorizations directly implements access control policies to block unauthorized access.
CWE-863Incorrect Authorization3,303Mandating policy-based enforcement reduces the chance of incorrect authorization logic being used.
CWE-639Authorization Bypass Through User-Controlled Key1,897Consistent enforcement of approved authorizations makes bypassing via user-controlled keys ineffective.
CWE-285Improper Authorization1,252The control requires checking and applying authorization decisions per policy, preventing improper authorization.
CWE-425Direct Request ('Forced Browsing')255Enforcing access for all logical requests prevents unauthorized direct access to protected resources.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-12480 KEV8.59.10.7832good
CVE-2025-6205 KEV8.09.10.6951good
CVE-2025-133157.19.80.8499good
CVE-2024-463106.89.10.8300good
CVE-2024-57968 KEV6.49.90.4106good
CVE-2015-101406.28.80.7387good
CVE-2015-101436.09.80.6745good
CVE-2024-122525.99.80.6649good
CVE-2012-100305.69.80.6098good
CVE-2025-24989 KEV5.58.20.3162good
CVE-2026-271804.99.80.4880good
CVE-2026-285154.48.80.4425good
CVE-2024-570494.09.80.3460good
CVE-2025-48572 KEV3.67.80.0021good
CVE-2024-125423.58.60.3039good
CVE-2024-559633.56.50.3723good
CVE-2025-663013.59.60.2622good
CVE-2026-20133 KEV UPD3.46.50.0136good
CVE-2025-40602 KEV3.36.60.0015good
CVE-2026-20253.27.50.2881good
CVE-2026-393393.19.10.2127good
CVE-2023-47179 UPD2.98.80.1915good
CVE-2025-118332.99.80.1525good
CVE-2026-318162.89.10.1643good
CVE-2024-123652.88.50.1826good

Other controls in family AC

AC-1 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-17 AC-18 AC-19 AC-2 AC-20 AC-21 AC-22 AC-23 AC-24 AC-25 AC-4 AC-5 AC-6 AC-7 AC-8 AC-9