SSP cleanup after catalog import
A GRC tool imported legacy IDs including AC-13. The HIPAA compliance team marks AC-13 Not Selected / Withdrawn and links evidence to AC-2, AU-6, AC-6, PS-7 so the control does not appear as an open gap.
AC-13 is not an active NIST SP 800-53 Revision 5 base control. The identifier appears in some legacy catalogs or as an unused numbering slot within the Access Control family, but organizations should not treat AC-13 as a selectable Rev. 5 baseline requirement. Historically this ID referred to "Supervision and Review — Access Control." In prior revisions AC-13 addressed supervision and review of access; Rev. 5 incorporates that intent into account management and audit review processes. Healthcare security programs, System Security Plans (SSPs), and HIPAA Security Rule mappings should cite the related active controls instead of inventing implementation evidence for AC-13.
Do not select AC-13 as an active Rev. 5 baseline control; document withdrawn/unused status and satisfy the underlying intent through the related active NIST controls listed for this identifier.
How this control shows up in healthcare and HIPAA-covered environments.
A GRC tool imported legacy IDs including AC-13. The HIPAA compliance team marks AC-13 Not Selected / Withdrawn and links evidence to AC-2, AU-6, AC-6, PS-7 so the control does not appear as an open gap.
An external assessor’s workbook still lists AC-13. The organization provides the Rev. 5 withdrawn/unused explanation and walks the assessor through related active controls rather than fabricating AC-13-specific procedures.
A BA security questionnaire requires "implement AC-13." Security responds that AC-13 is not an active Rev. 5 base control and maps answers to AC-2, AU-6, AC-6, PS-7, avoiding false attestation.
Auditors may still search by historical numbers. A clear withdrawn/unused statement plus mapped evidence on active controls is stronger than empty placeholder pages or forced "implementation" narratives for AC-13.
How this NIST control supports HIPAA Security Rule expectations.
No. AC-13 is not an active Rev. 5 base control. Satisfy the intent through related active controls (AC-2, AU-6, AC-6, PS-7) and map those to the HIPAA Security Rule.
Legacy catalogs and sequential family numbering often retain withdrawn or unused slots. This page documents that status so thin/placeholder content is not mistaken for a live requirement.
Show the Not Selected / Withdrawn rationale and the evidence package for the successor/related controls.
Related controls that commonly accompany AC-13.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.