HOME

AC-2 (3)

AC-2 (3) H M
Description

The information system automatically disables inactive accounts after [Assignment: organization-defined time period].

FedRAMP
  • H AC-2 (3) [35 days for user accounts]
  • M AC-2 (3) [90 days for user accounts]
DISA Cloud Computing SRG

35 days

Source:
DoD RMF TAG

Further Guidance

AC-2 (3) Requirement: The service provider defines the time period for non-user accounts (e.g., accounts associated with devices). The time periods are approved and accepted by the JAB/AO. Where user management is a function of the service, reports of activity of consumer users shall be made available.