| name | AC-22_publicly-accessible-content |
| description | Designate individuals authorized to make information publicly accessible; |
| category | authorization |
| version | 5.2.0 |
| author | cyberstrike-official |
| tags | ["nist","sp800-53","rev5","ac-22","ac"] |
| tech_stack | ["aws","azure","gcp","linux","windows"] |
| cwe_ids | ["CWE-284"] |
| chains_with | ["AC-3","AT-2","AT-3","AU-13"] |
| prerequisites | [] |
| severity_boost | {"AC-3":"Chain with AC-3 for comprehensive security coverage","AT-2":"Chain with AT-2 for comprehensive security coverage","AT-3":"Chain with AT-3 for comprehensive security coverage"} |
AC-22 Publicly Accessible Content
High-Level Description
Family: Access Control (AC)
Framework: NIST SP 800-53 Rev 5
In accordance with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines, the public is not authorized to have access to nonpublic information, including information protected under the PRIVACT and proprietary information. Publicly accessible content addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication. Posting information on non-organizational systems (e.g., non-organizational public websites, forums, and social media) is covered by organizational policy. While organizations may have individuals who are responsible for developing and implementing policies about the information that can be made publicly accessible, publicly accessible content addresses the management of the individuals who make such information publicly accessible.
What to Check
How to Test
Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for AC-22 implementation details. Verify the organization has documented how this control is satisfied.
Step 2: Validate Implementation
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
Tools
| Tool | Purpose | Usage |
|---|
| cloud-audit-mcp | Check IAM policies and access controls | cloud_audit_iam_policies |
| hackbrowser-mcp | Test web application access controls | browser_auth_test |
Remediation Guide