# AC-01 Policy and Procedures — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/ac-1

Canonical id: `ac-1` · family `AC`

> a. Develop, document, and disseminate to [organization-defined personnel or roles]: 1. [assignment] access control policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the access control policy and the associated access controls; b. Designate an [official] to manage the development, documentation, and dissemination of the access control policy and procedures; and c. Review and update the current access control: 1. Policy [frequency] and following [events]; and 2. Procedures [frequency] and following [events].

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class B
- certification class C
- certification class D

## Key Security Indicators that reach it

- `KSI-SVC-SIN` — Securing Information (Service Configuration)
  Information is encrypted or otherwise secured from unwanted access or modification.

## FedRAMP guidance

_No FedRAMP-specific guidance attaches to this control._
