Skip to main content
SUPPORTED EVIDENCETESTEDLast reviewed: 2026-07-01

AC-6: Employ the principle of least privilege allowing only authorized accesses necessary for assigned tasks

Vallum evidence mapping for NIST SP 800-53 AC-6 — employ the principle of least privilege allowing only authorized accesses necessary for assigned tasks. This page documents what evidence Vallum produces, what it does not produce, and what remains the customer's responsibility.

Source Attribution

Framework
NIST SP 800-53 Rev 5
Control ID
AC-6
Source Organization
NIST
Control Objective
Employ the principle of least privilege allowing only authorized accesses necessary for assigned tasks

Evidence Vallum Produces

Authorization receipts documenting each access decision, tenant-scoped permission records, and session lifecycle events

Evidence Vallum Does NOT Produce

Network-level access control logs, physical access records, or operating-system authentication events

Known Limitations

Vallum produces evidence relevant to this control but does not enforce the control at the infrastructure, network, or operating-system level. Evidence covers Vallum-managed operations only. Customer systems, third-party integrations, and infrastructure controls require separate evidence sources.

Your Responsibilities

Implement network-level access controls, manage user provisioning in identity provider, configure authorization policies, and review access periodically

External Controls Required

Identity provider (IdP), network firewall and segmentation, infrastructure monitoring, endpoint protection, and organizational security policies

Residual Risk

Vallum evidence covers authorization and evidence-layer operations. Gaps exist at infrastructure, network, and physical layers that require complementary controls. Time-of-check to time-of-use windows exist between evidence capture and verification.

Relevant Titan Components

Titan HandshakeTitan Verify

Related Content

Related Architectures

Need a detailed evidence mapping for your specific compliance program?

Request a Control Evidence Mapping

Legal boundary: This mapping is technical reference documentation. It does not constitute compliance certification, legal advice, or audit opinion. The control description is sourced from NIST's publicly available NIST SP 800-53 Rev 5 (public license) and summarized for educational reference. Consult qualified compliance professionals for your specific regulatory obligations.