{"id":1061,"date":"2024-07-16T20:25:57","date_gmt":"2024-07-16T20:25:57","guid":{"rendered":"https:\/\/www.tarleton.edu\/security-controls-catalog\/?page_id=1061"},"modified":"2026-08-24T21:49:13","modified_gmt":"2026-08-24T21:49:13","slug":"ac-14-permitted-actions-without-identification-or-authentication","status":"publish","type":"page","link":"https:\/\/www.tarleton.edu\/security-controls-catalog\/access-control-ac\/ac-14-permitted-actions-without-identification-or-authentication\/","title":{"rendered":"AC-14: Permitted Actions Without Identification or Authentication"},"content":{"rendered":"\n<h1 class=\"wp-block-heading has-large-font-size\">AC-14: Permitted Actions Without Identification or Authentication<\/h1>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" style=\"font-size:clamp(14px, 0.875rem + ((1vw - 3.2px) * 0.294), 16px);\"><strong>NIST Baseline: &nbsp;<\/strong>Low&nbsp;<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\" style=\"font-size:clamp(14px, 0.875rem + ((1vw - 3.2px) * 0.294), 16px);\"><strong>DIR Required By:<\/strong> 01\/20\/2023&nbsp;<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\" style=\"font-size:clamp(14px, 0.875rem + ((1vw - 3.2px) * 0.294), 16px);\"><strong>Review Date: \u00a0<\/strong>08\/24\/2026<\/h2>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>All actions on internal information resources will require a Tarleton-issued identifier that must be presented to the information resource before any actions are permitted to help ensure accountability with Tarleton procedures and business functions.&nbsp;&nbsp;&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li>Any exceptions to the above must be documented and approved by the Tarleton Chief Information Security Officer (CISO) or their designee.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li>Publicly accessible information resources such as public websites, information kiosks, and other situations where risk analysis demonstrates no need for individual accountability are exempt from the requirement of unique user identification as outlined in <a href=\"https:\/\/www.tarleton.edu\/security-controls-catalog\/access-control-ac\/ac-3-access-enforcement\/\" data-type=\"page\" data-id=\"968\">Control AC-3, Access Enforcement<\/a>.&nbsp;&nbsp;&nbsp;<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator aligncenter has-text-color has-tarleton-purple-color has-alpha-channel-opacity has-tarleton-purple-background-color has-background is-style-wide\"\/>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\"><strong>References\/Additional Resources<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">None.&nbsp; See any applicable internal procedures.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>AC-14: Permitted Actions Without Identification or Authentication NIST Baseline: &nbsp;Low&nbsp; DIR Required By: 01\/20\/2023&nbsp; Review Date: \u00a008\/24\/2026 References\/Additional Resources None.&nbsp; See any applicable internal procedures.&nbsp;<\/p>\n","protected":false},"author":1,"featured_media":580,"parent":871,"menu_order":14,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"inline_featured_image":false,"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","footnotes":""},"class_list":["post-1061","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"coauthors":[],"author_meta":{"author_link":"https:\/\/www.tarleton.edu\/security-controls-catalog\/author\/brian-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-3\/","display_name":"brian"},"relative_dates":{"created":"Posted 2 years ago","modified":"Updated 2 weeks ago"},"absolute_dates":{"created":"Posted on July 16, 2024","modified":"Updated on August 24, 2026"},"absolute_dates_time":{"created":"Posted on July 16, 2024 8:25 pm","modified":"Updated on August 24, 2026 9:49 pm"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/1061","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/comments?post=1061"}],"version-history":[{"count":1,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/1061\/revisions"}],"predecessor-version":[{"id":2697,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/1061\/revisions\/2697"}],"up":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/871"}],"wp:attachment":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/media?parent=1061"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}