| name | AC-16(1)_dynamic-attribute-association |
| description | Dynamically associate security and privacy attributes with [organization-defined] in accordance with the following security and privacy policies as in |
| category | authorization |
| version | 5.2.0 |
| author | cyberstrike-official |
| tags | ["nist","sp800-53","rev5","ac-16-1","ac","enhancement"] |
| tech_stack | ["aws","azure","gcp","linux","windows"] |
| cwe_ids | ["CWE-284"] |
| chains_with | [] |
| prerequisites | ["AC-16"] |
| severity_boost | {} |
AC-16(1) Dynamic Attribute Association
Enhancement of: AC-16
High-Level Description
Family: Access Control (AC)
Framework: NIST SP 800-53 Rev 5
Dynamic association of attributes is appropriate whenever the security or privacy characteristics of information change over time. Attributes may change due to information aggregation issues (i.e., characteristics of individual data elements are different from the combined elements), changes in individual access authorizations (i.e., privileges), changes in the security category of information, or changes in security or privacy policies. Attributes may also change situationally.
What to Check
How to Test
Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for AC-16(1) implementation details. Verify the organization has documented how this control is satisfied.
Step 2: Validate Implementation
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
Tools
| Tool | Purpose | Usage |
|---|
| cloud-audit-mcp | Check IAM policies and access controls | cloud_audit_iam_policies |
| hackbrowser-mcp | Test web application access controls | browser_auth_test |
Remediation Guide
Control Statement
Dynamically associate security and privacy attributes with [organization-defined] in accordance with the following security and privacy policies as information is created and combined: [organization-defined].
Implementation Guidance