Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family AC

AC-5Separation of Duties

Identify and document {{ insert: param, ac-05_odp }} ; and Define system access authorizations to support separation of duties.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (6)

ATT&CK techniques this control mitigates (165)

Weaknesses this control addresses (6)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control6,900+Defining authorizations to support separation of duties strengthens overall access control by preventing unauthorized combinations of actions within a single account.
CWE-269Improper Privilege Management3,400+By mandating division of duties across roles, the control enforces proper privilege management and prevents a single entity from controlling an entire sensitive process.
CWE-285Improper Authorization1,500+The control requires authorizations to be structured around separated duties, mitigating improper authorization that would otherwise allow one user to perform conflicting operations.
CWE-266Incorrect Privilege Assignment1,000+The control requires explicit definition of separated access authorizations, making incorrect privilege assignments that bundle conflicting duties harder to implement.
CWE-250Execution with Unnecessary Privileges300+Separation of duties prevents any single user from holding all privileges needed to complete a critical task, directly reducing execution with unnecessary privileges.
CWE-272Least Privilege Violation38Separation of duties is a direct mechanism to enforce least privilege by ensuring no individual receives more access than required for their isolated responsibilities.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-41244 KEV 8.57.80.0788partial
CVE-2026-296467.29.80.0037partial
CVE-2024-55968 6.78.80.0100partial
CVE-2025-23015 6.78.80.0098partial
CVE-2025-26467 6.68.80.0050partial
CVE-2024-4877 6.58.80.0042good
CVE-2024-39866 6.48.80.0024partial
CVE-2026-23526 6.48.80.0026partial
CVE-2026-0945 6.48.80.0022partial
CVE-2026-27314 6.48.80.0026partial
CVE-2026-10090 6.29.00.0025partial
CVE-2026-2459 6.08.10.0033partial
CVE-2026-24606.08.10.0028partial
CVE-2026-30792 6.08.10.0027good
CVE-2026-42406 6.08.70.0015partial
CVE-2026-483995.97.50.0046good
CVE-2023-52714 5.87.50.0034good
CVE-2024-7571 5.77.80.0026partial
CVE-2025-0889 5.77.80.0020good
CVE-2024-47045 5.67.80.0015good
CVE-2025-2297 5.67.80.0013good
CVE-2025-625875.68.20.0019partial
CVE-2025-625885.68.20.0019partial
CVE-2025-625895.68.20.0019partial
CVE-2025-625905.68.20.0019partial

Other controls in family AC

AC-1 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-17 AC-18 AC-19 AC-2 AC-20 AC-21 AC-22 AC-23 AC-24 AC-25 AC-3 AC-4 AC-6 AC-7 AC-8 AC-9