Delegation of Authority Matrix Validator
Regime

NIST SP 800-53 Rev 5: what it asks of an approval matrix

The separation of duties and least privilege controls, with account management, audit review and change control for the system lines of the matrix.

Quoted for every matrix.

Approval families anchored here

26
FamilyClause
Purchase ordersNIST SP 800-53 AC-5
Invoices with no purchase orderNIST SP 800-53 AC-5
Capital expenditureNIST SP 800-53 AC-5
Leases and rental commitmentsNIST SP 800-53 AC-5
Spend over budget and budget transfersNIST SP 800-53 AC-5
Payment run releaseNIST SP 800-53 AC-5
Urgent and manual paymentsNIST SP 800-53 AC-5
Bank account opening and changesNIST SP 800-53 AC-5
Vendor master data changeNIST SP 800-53 AC-5
Employee expense claimsNIST SP 800-53 AC-5
Payroll releaseNIST SP 800-53 AC-5
Journal entriesNIST SP 800-53 AC-5
Accruals and prepaymentsNIST SP 800-53 AC-5
Provisions and reservesNIST SP 800-53 AC-5
Write-offsNIST SP 800-53 AC-5
Reconciliation sign-offNIST SP 800-53 AC-5
FX, hedging and treasury dealsNIST SP 800-53 AC-5
Price and price list changesNIST SP 800-53 AC-5
Discounts and rebatesNIST SP 800-53 AC-5
Credit notesNIST SP 800-53 AC-5
Customer refundsNIST SP 800-53 AC-5
Customer credit limitsNIST SP 800-53 AC-5
Privileged system access grantsNIST SP 800-53 AC-6 · NIST SP 800-53 AC-2
User access review sign-offNIST SP 800-53 AC-2 · NIST SP 800-53 AU-6
Changes to production systemsNIST SP 800-53 CM-3 · NIST SP 800-53 CM-5
Changes to approval workflows and limits in the systemNIST SP 800-53 AC-3 · NIST SP 800-53 AU-6 · NIST SP 800-53 CM-5

NIST SP 800-53 Rev 5: every clause cited, quoted

8 of the 300 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

NIST SP 800-53 AC-2 Account management

Requires accounts to be managed across their full life cycle: permitted and prohibited account types defined, account managers assigned, membership prerequisites and approvals required, accounts created, modified, disabled and removed under documented criteria, usage monitored, and access reauthorized on a defined frequency.

What an auditor asks to see: Account type register showing which account types are permitted and which are prohibited; Provisioning and deprovisioning tickets carrying documented approval by the responsible party; Leaver reconciliation between the human resources record and account disablement dates; Periodic account recertification results with evidence that revocations were executed; Monitoring output for atypical account usage and for dormant accounts
Where matrices usually fall short: Shared and service accounts sit outside the joiner mover leaver process entirely; Recertification is signed off in bulk without any account actually being removed; Contractor and third party accounts outlive the engagement because no end date is held
Source: NIST SP 800-53 Rev 5
NIST SP 800-53 AC-3 Access enforcement

Requires the system to technically enforce the access authorizations that policy has approved, so that logical access to information and system resources is permitted only where an approved authorization exists.

What an auditor asks to see: Access control configuration export showing permissions as enforced by the system; Mapping from approved authorization records to the entitlements actually held; Test results demonstrating denial of access outside an approved authorization; Evidence of enforcement at each layer including database, storage and administrative interfaces
Where matrices usually fall short: Enforcement present in the application but absent at the database or storage layer beneath it; Entitlements accumulate through role changes so effective access exceeds what was approved; Emergency or break glass paths bypass enforcement without compensating logging
Source: NIST SP 800-53 Rev 5
NIST SP 800-53 AC-5 Separation of duties

Requires the organization to identify and document the individual duties that must be kept apart to limit malevolent activity without collusion, and to define system access authorizations so that those duties cannot be exercised by one person.

What an auditor asks to see: Documented conflicting duty pairs for the mission and system in question; Role definitions and entitlement mapping showing conflicting duties are not held together; Toxic combination report from the identity system or a manual conflict analysis; Approved exceptions with the compensating detective controls applied
Where matrices usually fall short: Conflicting duties named for finance processes only and never for system administration; Small teams create unavoidable conflicts that are tolerated rather than documented and compensated; Separation enforced at role definition but broken by direct entitlement grants
Source: NIST SP 800-53 Rev 5
NIST SP 800-53 AC-6 Least privilege

Requires access for users and for processes acting for them to be limited to what their assigned tasks actually need, so that no account, role or process holds privileges beyond the minimum required to do its job.

What an auditor asks to see: Role to entitlement mapping showing privileges justified against job function; Privileged account inventory with business justification for each; Review evidence where excess privilege was identified and removed; Configuration showing service and application accounts run without administrative rights
Where matrices usually fall short: Administrator rights granted as a default to speed up troubleshooting and never revoked; Service accounts run with far more privilege than the application needs; Least privilege applied to people while automation and pipeline identities are unrestricted
Source: NIST SP 800-53 Rev 5
NIST SP 800-53 AU-6 Audit record review, analysis, and reporting

Requires audit records to be reviewed and analysed on a defined frequency for indications of organization-defined inappropriate or unusual activity and its likely impact, findings to be reported to defined personnel, and the depth of review to be increased when credible information changes the risk.

What an auditor asks to see: Defined review frequency and the activity indicators being looked for; Completed review records with reviewer, date and findings; Reports issued to the defined recipients and evidence of follow-up; Record of a review level adjustment made in response to changed risk
Where matrices usually fall short: Review is automated alerting only, with no periodic analytical review for slow patterns; Findings recorded but never reported to anyone able to act; No mechanism to raise review intensity when threat information changes
Source: NIST SP 800-53 Rev 5
NIST SP 800-53 CM-3 Configuration change control

Requires the types of change that fall under configuration control to be defined, proposed changes to be reviewed and approved or rejected with explicit consideration of security and privacy impact, decisions and implemented changes to be documented, change records to be retained for a defined period, and change activity to be monitored and reviewed by the responsible body.

What an auditor asks to see: Documented definition of which change types are configuration controlled; Change records showing security and privacy impact considered before approval; Change advisory board or approver minutes recording decisions; Retention evidence for change records against the defined period; Post-implementation review or monitoring output for change activity
Where matrices usually fall short: Emergency changes bypass approval and are never retrospectively documented; Impact analysis recorded as a tick box with no security reasoning behind it; Infrastructure as code changes merge without passing through the same change control
Source: NIST SP 800-53 Rev 5
NIST SP 800-53 CM-5 Access restrictions for change

Requires physical and logical access restrictions on who may make changes to the system to be defined, documented, approved and actually enforced, so that only authorized personnel can alter the system.

What an auditor asks to see: Documented and approved restrictions on who may change what; Access control configuration for production change paths and deployment pipelines; Records showing enforcement, for example rejected unauthorized deployments; Review of privileged change access against the approved list
Where matrices usually fall short: Developers hold standing write access to production alongside the pipeline; Restrictions documented but not enforced, so the pipeline can be bypassed manually; Physical access to equipment rooms not treated as a change path
Source: NIST SP 800-53 Rev 5
NIST SP 800-53 PS-5 Personnel transfer

Requires that when individuals are reassigned or transferred internally their existing logical and physical access is reviewed and confirmed as still needed, defined transfer actions are initiated within a defined period, authorizations are modified to match the new role, and defined personnel are notified within a defined period.

What an auditor asks to see: Transfer process documentation with the defined actions and timeframes; Records of access reviews performed at transfer; Evidence of access modification or removal following the review; Notification records to the defined personnel within the required period
Where matrices usually fall short: Access accumulates across roles because transfer only ever adds entitlements; Transfer treated as a human resources event that never reaches system owners; Notification timeframes undefined, so changes lag the transfer by months
Source: NIST SP 800-53 Rev 5