AC-2 Account Management: Same Answer, Different Artifact
Two agencies. Same checklist answer: account management reviews are conducted quarterly in accordance with AC-2. Both rated themselves compliant.
The auditor asked for the records.
Agency A produced a spreadsheet with dates, account names, reviewer initials, and disposition notes for each review cycle. The last review was six weeks ago. The one before that was three months prior. Each row showed what action was taken — account disabled, access scope reduced, no change with rationale noted.
Agency B produced the policy. Section 4.2: user accounts will be reviewed quarterly by the LASO. It was signed. It was current. It said exactly what the control requires.
The auditor noted the finding: policy present, evidence of operation absent. AC-2(j) requires that the organization reviews accounts in accordance with the defined frequency. The policy establishes the frequency. The review record demonstrates the control ran.
What the control actually requires
AC-2 is marked Existing and Priority 1. It has been sanctionable since October 1, 2024. The control requires the organization to monitor, review, and report on account usage in accordance with organizational policy — not to have a policy that says monitoring, reviewing, and reporting will occur.
Six of AC-2's sub-requirements address active management activities: creating accounts with proper authorization, disabling accounts when no longer needed, reviewing accounts at defined intervals, monitoring accounts for atypical usage, reporting on account activity. Each one has an evidence trail. A signed policy addresses none of them.
What the auditor is looking for
The evidence set for AC-2 includes: the account inventory with roles and access levels documented; the review log showing when reviews occurred, who conducted them, and what was found; records of account modifications, disablements, or removals with authorization and dates; and documentation that accounts for personnel who separated or changed roles were acted upon within the required timeframe.
A quarterly review that happened but was not recorded is indistinguishable from a quarterly review that did not happen.
The common failure mode
Most agencies have the policy. The policy was written when the system was stood up, reviewed by legal, signed by the chief. It says the right things. Nobody scheduled the actual reviews into a recurring calendar with a documentation requirement attached. The first time anyone looks at whether the reviews happened is when an auditor asks.
Fixing this does not require new technology. It requires a calendar entry, a named reviewer, a simple log, and a process for acting on what the review finds. The evidence is the log. Without it, the policy is a statement of intent, not evidence of operation.
Written by Dr. Alexis W. Perdereaux-Weekes
DBA · CISA · CISM · CRISC · CDPSE
Founder, CJIS360 LLC
Sources: CJIS Security Policy v6.1, 06/25/2026 — AC-2 Account Management; AC-2(j) Account Review; §1.4 Terminology Used in This Document.