AC-22 Publicly Accessible Content

Access Control

Low Moderate High

Description

a. Designate individuals authorized to make information publicly accessible; b. Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information; c. Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included; and d. Review the content on the publicly accessible system for nonpublic information [Assignment: organization-defined frequency] and remove such information, if discovered.

Supplemental Guidance

In accordance with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines, the public is not authorized to have access to nonpublic information, including information protected under the Privacy Act and proprietary information. This control addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication.

Changes from Rev 4

No significant changes from Rev 4.

Compliance Mappings

COBIT 2019

DSS05

NIS2 Directive

Art. 21(2)(i)

MAS TRM

9

BSI IT-Grundschutz

ORP.4

RBI CSF

Annex1.8

UAE IA

T9

Qatar NIA

AC

BoG CISD

CISD-VIII

BCBS 239

Principle 11

FFIEC IS

II.C.13

CMMC 2.0

AC

Basel SCO60

SCO60.70SCO60.71SCO60.72