Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family AC

AC-5Separation of Duties

Identify and document {{ insert: param, ac-05_odp }} ; and Define system access authorizations to support separation of duties.

Last updated: 19 May 2026 14:18 UTC

Implementations targeting this control (6)

ATT&CK techniques this control mitigates (165)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control4,905Defining authorizations to support separation of duties strengthens overall access control by preventing unauthorized combinations of actions within a single account.
CWE-269Improper Privilege Management2,936By mandating division of duties across roles, the control enforces proper privilege management and prevents a single entity from controlling an entire sensitive process.
CWE-285Improper Authorization1,252The control requires authorizations to be structured around separated duties, mitigating improper authorization that would otherwise allow one user to perform conflicting operations.
CWE-266Incorrect Privilege Assignment836The control requires explicit definition of separated access authorizations, making incorrect privilege assignments that bundle conflicting duties harder to implement.
CWE-250Execution with Unnecessary Privileges311Separation of duties prevents any single user from holding all privileges needed to complete a critical task, directly reducing execution with unnecessary privileges.
CWE-272Least Privilege Violation26Separation of duties is a direct mechanism to enforce least privilege by ensuring no individual receives more access than required for their isolated responsibilities.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2026-297892.09.90.0007partial
CVE-2026-276681.88.80.0005good
CVE-2026-290731.88.80.0007partial
CVE-2026-309441.88.80.0006partial
CVE-2026-264161.88.80.0005good
CVE-2026-258591.88.80.0002partial
CVE-2026-345871.68.10.0003partial
CVE-2026-405911.47.10.0003partial
CVE-2025-08491.36.30.0003partial
CVE-2025-256160.94.30.0057partial

Other controls in family AC

AC-1 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-17 AC-18 AC-19 AC-2 AC-20 AC-21 AC-22 AC-23 AC-24 AC-25 AC-3 AC-4 AC-6 AC-7 AC-8 AC-9