<?xml version="1.0" encoding="UTF-8"?><!--Serialized by the GTRI Trustmark Framework API, version: 1.4.74--><tf:TrustInteroperabilityProfile xmlns:tf="https://trustmarkinitiative.org/specifications/trustmark-framework/1.4/schema/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tips/nist-sp-800-53-r4-security-control-ac-2_-account-management/4/</tf:Identifier><tf:Name>NIST SP 800-53 r4 Security Control AC-2: Account Management</tf:Name><tf:Version>4</tf:Version><tf:Description>Profile of requirements corresponding to NIST Special Publication 800-53, r4, Security Control AC-2: Account Management. Applicable to LOW impact, MODERATE impact, and HIGH impact systems.</tf:Description><tf:PublicationDateTime>2021-04-26T00:00:00.000Z</tf:PublicationDateTime><tf:Primary>false</tf:Primary><tf:LegalNotice>This document and the information contained herein is provided on an "AS IS" basis, and the Georgia Tech Research Institute disclaims all warranties, express or implied, including but not limited to any warranty that the use of the information herein will not infringe any rights or any implied warranties or merchantability or fitness for a particular purpose. In addition, the Georgia Tech Research Institute disclaims legal liability for any loss incurred as a result of the use or reliance on the document or the information contained herein.</tf:LegalNotice><tf:Issuer><tf:Identifier>https://trustmarkinitiative.org/</tf:Identifier><tf:Name>TMI</tf:Name><tf:Contact><tf:Kind>PRIMARY</tf:Kind><tf:Responder></tf:Responder><tf:Email>help@trustmarkinitiative.org</tf:Email><tf:Telephone>555-555-5555</tf:Telephone><tf:WebsiteURL>https://trustmarkinitiative.org/</tf:WebsiteURL></tf:Contact></tf:Issuer><tf:Keywords><tf:Keyword>800-53</tf:Keyword><tf:Keyword>Access Control</tf:Keyword><tf:Keyword>Account Management</tf:Keyword><tf:Keyword>High</tf:Keyword><tf:Keyword>Low</tf:Keyword><tf:Keyword>Moderate</tf:Keyword><tf:Keyword>NIST</tf:Keyword><tf:Keyword>P1</tf:Keyword><tf:Keyword>Security</tf:Keyword></tf:Keywords><tf:References><tf:TrustmarkDefinitionRequirement tf:id="TD_ref1"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/account-monitoring/1.0/</tf:Identifier><tf:Number>1</tf:Number><tf:Name>Account Monitoring</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for account monitoring as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref2"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/reissuance-of-shared-group-credentials/1.0/</tf:Identifier><tf:Number>2</tf:Number><tf:Name>Reissuance of Shared/Group Credentials</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for reissuance of shared/group credentials as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref3"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/account-manager-notification/1.0/</tf:Identifier><tf:Number>3</tf:Number><tf:Name>Account Manager Notification</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for account manager notification as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref4"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/specified-privileges-for-each-account/1.0/</tf:Identifier><tf:Number>4</tf:Number><tf:Name>Specified Privileges For Each Account</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for specified privileges for each account as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref5"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/account-managers/1.0/</tf:Identifier><tf:Number>5</tf:Number><tf:Name>Account Managers</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for account managers as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref6"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/account-creation-approvals/1.0/</tf:Identifier><tf:Number>6</tf:Number><tf:Name>Account Creation Approvals</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for account creation approvals as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref7"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/identified-account-types/1.0/</tf:Identifier><tf:Number>7</tf:Number><tf:Name>Identified Account Types</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for identified account types as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref8"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/group-and-role-membership/1.0/</tf:Identifier><tf:Number>8</tf:Number><tf:Name>Group and Role Membership</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for group and role membership as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref9"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/defined-procedures-for-account-management/1.0/</tf:Identifier><tf:Number>9</tf:Number><tf:Name>Defined Procedures for Account Management</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for defined procedures for account management as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref10"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/access-authorizations/1.0/</tf:Identifier><tf:Number>10</tf:Number><tf:Name>Access Authorizations</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for access authorizations as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref11"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/review-of-accounts/1.0/</tf:Identifier><tf:Number>11</tf:Number><tf:Name>Review of Accounts</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for review of accounts as related to overall access control requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement></tf:References><tf:TrustExpression><![CDATA[TD_ref1 and TD_ref2 and TD_ref3 and TD_ref4 and TD_ref5 and TD_ref6 and TD_ref7 and TD_ref8 and TD_ref9 and TD_ref10 and TD_ref11]]></tf:TrustExpression><tf:Sources><tf:Source tf:id="Source-2112165102"><tf:Identifier>SP800-53R4</tf:Identifier><tf:Reference>NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, National Institute of Standards and Technology, April 2013 (Includes updates as of 01-15-2014). Available at &lt;a href="http://dx.doi.org/10.6028/NIST.SP.800-53r4"&gt;http://dx.doi.org/10.6028/NIST.SP.800-53r4&lt;/a&gt;.</tf:Reference></tf:Source></tf:Sources></tf:TrustInteroperabilityProfile>