id: "AC-02(07)" title: "Privileged User Accounts" family: "AC" family_name: "Access Control" sort_id: "ac-02.07" priority: "P1" implementation_level: "organization" parent: "AC-02" enhancement: True


Establish and administer privileged user accounts in accordance with {{ insert: param, ac-02.07_odp }};

Monitor privileged role or attribute assignments;

Monitor changes to roles or attributes; and

Revoke access when privileged role or attribute assignments are no longer appropriate.

Guidance

Privileged roles are organization-defined roles assigned to individuals that allow those individuals to perform certain security-relevant functions that ordinary users are not authorized to perform. Privileged roles include key management, account management, database administration, system and network administration, and web administration. A role-based access scheme organizes permitted system access and privileges into roles. In contrast, an attribute-based access scheme specifies allowed system access and privileges based on attributes.

Assessment Objective: privileged user accounts are established and administered in accordance with {{ insert: param, ac-02.07_odp }};

Assessment Objective: privileged role or attribute assignments are monitored;

Assessment Objective: changes to roles or attributes are monitored;

Assessment Objective: access is revoked when privileged role or attribute assignments are no longer appropriate.

Access control policy

procedures addressing account management

system design documentation

system configuration settings and associated documentation

system-generated list of privileged user accounts and associated roles

records of actions taken when privileged role assignments are no longer appropriate

system audit records

audit tracking and monitoring reports

system monitoring records

system security plan

other relevant documents or records

Organizational personnel with account management responsibilities

system/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing account management functions

mechanisms monitoring privileged role assignments