id: "AC-02(07)" title: "Privileged User Accounts" family: "AC" family_name: "Access Control" sort_id: "ac-02.07" priority: "P1" implementation_level: "organization" parent: "AC-02" enhancement: True
Establish and administer privileged user accounts in accordance with {{ insert: param, ac-02.07_odp }};
Monitor privileged role or attribute assignments;
Monitor changes to roles or attributes; and
Revoke access when privileged role or attribute assignments are no longer appropriate.
Guidance
Privileged roles are organization-defined roles assigned to individuals that allow those individuals to perform certain security-relevant functions that ordinary users are not authorized to perform. Privileged roles include key management, account management, database administration, system and network administration, and web administration. A role-based access scheme organizes permitted system access and privileges into roles. In contrast, an attribute-based access scheme specifies allowed system access and privileges based on attributes.
Assessment Objective: privileged user accounts are established and administered in accordance with {{ insert: param, ac-02.07_odp }};
Assessment Objective: privileged role or attribute assignments are monitored;
Assessment Objective: changes to roles or attributes are monitored;
Assessment Objective: access is revoked when privileged role or attribute assignments are no longer appropriate.
Access control policy
procedures addressing account management
system design documentation
system configuration settings and associated documentation
system-generated list of privileged user accounts and associated roles
records of actions taken when privileged role assignments are no longer appropriate
system audit records
audit tracking and monitoring reports
system monitoring records
system security plan
other relevant documents or records
Organizational personnel with account management responsibilities
system/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing account management functions
mechanisms monitoring privileged role assignments