AC-13 Access Control

AC-13 Withdrawn / Not Selected in Current Baseline

Low Risk Easy Low Cost

AC-13 is not an active NIST SP 800-53 Revision 5 base control. The identifier appears in some legacy catalogs or as an unused numbering slot within the Access Control family, but organizations should not treat AC-13 as a selectable Rev. 5 baseline requirement. Historically this ID referred to "Supervision and Review — Access Control." In prior revisions AC-13 addressed supervision and review of access; Rev. 5 incorporates that intent into account management and audit review processes. Healthcare security programs, System Security Plans (SSPs), and HIPAA Security Rule mappings should cite the related active controls instead of inventing implementation evidence for AC-13.

Control Objective

Do not select AC-13 as an active Rev. 5 baseline control; document withdrawn/unused status and satisfy the underlying intent through the related active NIST controls listed for this identifier.

Implementation Guidance

  1. Confirm in NIST SP 800-53 Rev. 5 (and overlays you use) that AC-13 is withdrawn or not defined as a base control.
  2. Mark AC-13 as Not Selected / Withdrawn in the SSP control catalog with a short rationale.
  3. Map any legacy checklist rows that still cite AC-13 to related active controls: AC-2, AU-6, AC-6, PS-7.
  4. Update HIPAA Security Rule crosswalks so assessors are pointed at live AC/AU/CM/IA/RA/SC/SI controls.
  5. Remove AC-13 from vulnerability scanners, GRC templates, and RFP questionnaires that imply it is current.
  6. If a partner still asks for AC-13, provide the withdrawn note plus evidence against the successor controls.
  7. Keep a one-page family appendix for auditors who search by legacy ID.
  8. Re-check after catalog upgrades so placeholders are not reintroduced as "open findings."

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

SSP cleanup after catalog import

A GRC tool imported legacy IDs including AC-13. The HIPAA compliance team marks AC-13 Not Selected / Withdrawn and links evidence to AC-2, AU-6, AC-6, PS-7 so the control does not appear as an open gap.

Assessor asks for AC-13 evidence

An external assessor’s workbook still lists AC-13. The organization provides the Rev. 5 withdrawn/unused explanation and walks the assessor through related active controls rather than fabricating AC-13-specific procedures.

Vendor questionnaire hygiene

A BA security questionnaire requires "implement AC-13." Security responds that AC-13 is not an active Rev. 5 base control and maps answers to AC-2, AU-6, AC-6, PS-7, avoiding false attestation.

Best Practices

  • Prefer Rev. 5 (or your authorized overlay) as the source of truth for control IDs.
  • Record Not Selected with rationale for withdrawn/unused IDs.
  • Keep a legacy-ID → active-control map for assessors.
  • Do not invent policies solely to "satisfy" withdrawn numbers.
  • Align HIPAA mappings to active controls only.
  • Purge withdrawn IDs from automated scanners and scorecards.

Common Gaps & Violations

  • Leaving AC-13 as "Partially Implemented" with empty evidence.
  • Writing boilerplate procedures for a control that does not exist in Rev. 5.
  • Failing HIPAA assessments because the crosswalk still keys off withdrawn IDs.
  • Vendors claiming AC-13 certification as if it were current.
  • Placeholder title "Access Control" left unpublished with empty use cases.

Required Documentation

  • SSP entry: AC-13 Not Selected / Withdrawn (rationale)
  • Legacy ID mapping table to active controls
  • Updated HIPAA–NIST crosswalk pages
  • Assessor FAQ / appendix for withdrawn IDs
  • Change ticket removing AC-13 from GRC open items

How to Test & Validate

  1. Search SSP and GRC for AC-13; expect Not Selected / Withdrawn, not Open.
  2. Confirm related active controls AC-2, AU-6, AC-6, PS-7 have owners and evidence.
  3. Spot-check HIPAA crosswalk for live control IDs only.
  4. Verify scanners/questionnaires do not score AC-13 as failed.
  5. Ask a sample assessor question path: legacy ID → successor evidence.

Audit Considerations

Auditors may still search by historical numbers. A clear withdrawn/unused statement plus mapped evidence on active controls is stronger than empty placeholder pages or forced "implementation" narratives for AC-13.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Analysis / Risk Management — map safeguards to controls that actually exist and are operated.
  • 164.306 Security Standards: General Rules — reasonable and appropriate measures; do not chase withdrawn catalog slots.
  • 164.316 Policies and Procedures — documentation should reflect the current control baseline used by the organization.
  • Assessment practice: HIPAA evaluations should map to active NIST SP 800-53 Rev. 5 controls (and HIPAA implementation specifications), not withdrawn IDs like AC-13.

Compliance Tips

  • Add AC-13 to a "withdrawn/unused" appendix rather than the implementable baseline list.
  • Train GRC admins not to reopen withdrawn IDs after tool upgrades.
  • When in doubt, implement and evidence AC-2, AU-6, AC-6, PS-7.

Frequently Asked Questions

Should we implement AC-13 for HIPAA?

No. AC-13 is not an active Rev. 5 base control. Satisfy the intent through related active controls (AC-2, AU-6, AC-6, PS-7) and map those to the HIPAA Security Rule.

Why is AC-13 in our database?

Legacy catalogs and sequential family numbering often retain withdrawn or unused slots. This page documents that status so thin/placeholder content is not mistaken for a live requirement.

What do we show an assessor who insists on AC-13?

Show the Not Selected / Withdrawn rationale and the evidence package for the successor/related controls.

References & Resources

  • NIST SP 800-53 Rev. 5 control catalog (withdrawn / not defined entries)
  • Related active controls: AC-2, AU-6, AC-6, PS-7
  • NIST SP 800-53B control baselines (confirm non-selection)

Need Help Implementing AC-13?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.