id: "AC-06(03)" title: "Network Access to Privileged Commands" family: "AC" family_name: "Access Control" sort_id: "ac-06.03" priority: "P1" implementation_level: "organization" parent: "AC-06" enhancement: True


Statement

Authorize network access to {{ insert: param, ac-06.03_odp.01 }} only for {{ insert: param, ac-06.03_odp.02 }} and document the rationale for such access in the security plan for the system.

Guidance

Network access is any access across a network connection in lieu of local access (i.e., user being physically present at the device).

Assessment Objective: network access to {{ insert: param, ac-06.03_odp.01 }} is authorized only for {{ insert: param, ac-06.03_odp.02 }};

Assessment Objective: the rationale for authorizing network access to privileged commands is documented in the security plan for the system.

Access control policy

procedures addressing least privilege

system configuration settings and associated documentation

system audit records

list of operational needs for authorizing network access to privileged commands

system security plan

other relevant documents or records

Organizational personnel with responsibilities for defining least privileges necessary to accomplish specified tasks

organizational personnel with information security responsibilities

Mechanisms implementing least privilege functions