AC-6(1) Access Control

AC-6(1) Authorize Access to Security Functions

Critical Risk Moderate Low Cost

AC-6(1) requires authorizing access to organization-defined security functions and security-relevant information. Unlike general least privilege, this enhancement forces an explicit authorization step for security functions — audit administration, authentication policy, cryptographic controls, and access-control administration on systems that protect ePHI. Informal 'IT can do everything' fails this control.

Control Objective

Grant access to security functions only through documented authorization so the set of people who can change ePHI protections stays intentional and minimal.

Implementation Guidance

  1. List security functions per platform (EHR security, IdP policy, SIEM admin, firewall, key management).
  2. Name authorizing officials for each function class (CISO, security manager, system owner).
  3. Require ticketed approval before assigning security-function roles.
  4. Use separate security-admin accounts; forbid daily clinical IDs from holding these rights.
  5. Recertify security-function access monthly or quarterly.
  6. Log use of security functions (pairs with AC-6(9)).
  7. Remove access immediately on role change (AC-3(8)/PS-5).
  8. Document interim emergency security access with expiry.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

New SIEM admin

Analyst promoted to detection engineering receives SIEM admin only after CISO designee approves AC-6(1) authorization — not via informal Slack ask.

EHR security workbench

Only three named security engineers hold the role; each annual recert lists business justification tied to job duties.

Cloud IAM policy admin

Subscription-level IAM rights to the PHI analytics project require security authorization distinct from general DevOps contributor rights.

Best Practices

  • Explicit authorization records for security roles.
  • Small standing set of security admins.
  • Monthly recert for Critical platforms.
  • Separate accounts for security functions.
  • No shared security-admin credentials.
  • Align with AC-3(1) privileged function restrictions.

Common Gaps & Violations

  • Domain Admins automatically get every security console.
  • Security roles granted by peer admins without record.
  • Standing vendor security access.
  • No recertification of who can disable auditing.
  • Helpdesk 'god mode' including auth policy changes.

Required Documentation

  • Security function inventory
  • Authorization procedure and approving roles
  • Current security-function access roster
  • Recertification records
  • Emergency security-access procedure

How to Test & Validate

  1. Compare security-admin group membership to authorization tickets.
  2. Confirm unauthorized IT staff cannot open security functions.
  3. Review last recert completion and removals.
  4. Sample emergency grants for expiry.
  5. Verify security-function assignments use dedicated accounts.

Audit Considerations

Who can turn off logging or change MFA policy is a favorite assessor question. Missing authorization evidence for those roles is an AC-6(1) failure.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(4) Information Access Management — authorize access to systems that manage ePHI access.
  • 164.312(b) Audit Controls — protect who administers auditing.
  • 164.308(a)(3) Workforce Security — clearance/authorization for sensitive duties.
  • 164.312(a)(1) Access Control — limit administrative access paths.

Compliance Tips

  • Keep a one-page roster of security-function admins for auditors.
  • Tie AC-6(1) approvals to the same CAB or IAM tool used for other privileged grants.
  • Never inherit security rights from broad Domain Admin alone without review.

Frequently Asked Questions

Are application config rights 'security functions'?

Pure content config may not be; anything affecting authN/authZ/audit/crypto is.

Can MSSP staff hold these rights?

Yes with BAA, named users, authorization, and monitoring — not shared generic logins.

How is this different from AC-3(1)?

AC-3(1) restricts privileged functions technically; AC-6(1) emphasizes authorizing who gets security-function access under least privilege.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-6(1)
  • Related: AC-3(1), AC-3(5), AC-6, AC-6(9), AU-9

Need Help Implementing AC-6(1)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.