Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

AC-22 — Publicly Accessible Content

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

0Enhancements
1Parameters
3Baseline memberships
3Assessment methods

AC — Access Control · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Designate individuals authorized to make information publicly accessible;
  2. b.Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
  3. c.Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included; and
  4. d.Review the content on the publicly accessible system for nonpublic information [Organization-defined: frequency] and remove such information, if discovered.
Official NIST discussion

Discussion

In accordance with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines, the public is not authorized to have access to nonpublic information, including information protected under the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) and proprietary information. Publicly accessible content addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication. Posting information on non-organizational systems (e.g., non-organizational public websites, forums, and social media) is covered by organizational policy. While organizations may have individuals who are responsible for developing and implementing policies about the information that can be made publicly accessible, publicly accessible content addresses the management of the individuals who make such information publicly accessible.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

frequencythe frequency at which to review the content on the publicly accessible system for non-public information is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Publicly Accessible Content as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity, authorization, least privilege, session boundaries, and access lifecycle governance.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • access approvals and entitlement records
  • role and group configuration exports
  • periodic access review results
  • authentication and authorization logs

Common failure patterns

  • standing privileges that outlive business need
  • shared or orphaned accounts
  • access rules implemented differently across systems
  • approvals that cannot be traced to actual permissions

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. AC-22a.designated individuals are authorized to make information publicly accessible;
  2. AC-22b.authorized individuals are trained to ensure that publicly accessible information does not contain non-public information;
  3. AC-22c.the proposed content of information is reviewed prior to posting onto the publicly accessible system to ensure that non-public information is not included;
  4. AC-22d.
    1. AC-22d.[01]the content on the publicly accessible system is reviewed for non-public information [Organization-defined: frequency];
    2. AC-22d.[02]non-public information is removed from the publicly accessible system, if discovered.

Examine

  • Access control policy
  • procedures addressing publicly accessible content
  • list of users authorized to post publicly accessible content on organizational systems
  • training materials and/or records
  • records of publicly accessible information reviews
  • records of response to non-public information on public websites
  • system audit logs
  • security awareness training records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for managing publicly accessible information posted on organizational systems
  • organizational personnel with information security responsibilities

Test

  • Mechanisms implementing management of publicly accessible content
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official CUI requirement crosswalk

Related NIST SP 800-171 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Source record

Authoritative sources