AC-06(07) Review of User Privileges

(a) Review ac-06.07_odp.01 the privileges assigned to ac-06.07_odp.02 to validate the need for such privileges; and

(b) Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs.

Parameter ID Definition
ac-06.07_odp.01 frequency
ac-06.07_odp.02 roles and classes



The need for certain assigned user privileges may change over time to reflect changes in organizational mission and business functions, environments of operation, technologies, or threats. A periodic review of assigned user privileges is necessary to determine if the rationale for assigning such privileges remains valid. If the need cannot be revalidated, organizations take appropriate corrective actions.

