Control statement
- a.Designate individuals authorized to make information publicly accessible;
- b.Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
- c.Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included; and
- d.Review the content on the publicly accessible system for nonpublic information [Organization-defined: frequency] and remove such information, if discovered.
Discussion
In accordance with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines, the public is not authorized to have access to nonpublic information, including information protected under the [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) and proprietary information. Publicly accessible content addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication. Posting information on non-organizational systems (e.g., non-organizational public websites, forums, and social media) is covered by organizational policy. While organizations may have individuals who are responsible for developing and implementing policies about the information that can be made publicly accessible, publicly accessible content addresses the management of the individuals who make such information publicly accessible.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Publicly Accessible Content as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity, authorization, least privilege, session boundaries, and access lifecycle governance.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- access approvals and entitlement records
- role and group configuration exports
- periodic access review results
- authentication and authorization logs
Common failure patterns
- standing privileges that outlive business need
- shared or orphaned accounts
- access rules implemented differently across systems
- approvals that cannot be traced to actual permissions
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- AC-22a.designated individuals are authorized to make information publicly accessible;
- AC-22b.authorized individuals are trained to ensure that publicly accessible information does not contain non-public information;
- AC-22c.the proposed content of information is reviewed prior to posting onto the publicly accessible system to ensure that non-public information is not included;
- AC-22d.
- AC-22d.[01]the content on the publicly accessible system is reviewed for non-public information [Organization-defined: frequency];
- AC-22d.[02]non-public information is removed from the publicly accessible system, if discovered.
Examine
- Access control policy
- procedures addressing publicly accessible content
- list of users authorized to post publicly accessible content on organizational systems
- training materials and/or records
- records of publicly accessible information reviews
- records of response to non-public information on public websites
- system audit logs
- security awareness training records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with responsibilities for managing publicly accessible information posted on organizational systems
- organizational personnel with information security responsibilities
Test
- Mechanisms implementing management of publicly accessible content
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related NIST SP 800-171 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.