id: "AC-06(03)" title: "Network Access to Privileged Commands" family: "AC" family_name: "Access Control" sort_id: "ac-06.03" priority: "P1" implementation_level: "organization" parent: "AC-06" enhancement: True
Statement
Authorize network access to {{ insert: param, ac-06.03_odp.01 }} only for {{ insert: param, ac-06.03_odp.02 }} and document the rationale for such access in the security plan for the system.
Guidance
Network access is any access across a network connection in lieu of local access (i.e., user being physically present at the device).
Assessment Objective: network access to {{ insert: param, ac-06.03_odp.01 }} is authorized only for {{ insert: param, ac-06.03_odp.02 }};
Assessment Objective: the rationale for authorizing network access to privileged commands is documented in the security plan for the system.
Access control policy
procedures addressing least privilege
system configuration settings and associated documentation
system audit records
list of operational needs for authorizing network access to privileged commands
system security plan
other relevant documents or records
Organizational personnel with responsibilities for defining least privileges necessary to accomplish specified tasks
organizational personnel with information security responsibilities
Mechanisms implementing least privilege functions