id: "AC-06(05)" title: "Privileged Accounts" family: "AC" family_name: "Access Control" sort_id: "ac-06.05" priority: "P1" implementation_level: "organization" parent: "AC-06" enhancement: True
Statement
Restrict privileged accounts on the system to {{ insert: param, ac-06.05_odp }}.
Guidance
Privileged accounts, including super user accounts, are typically described as system administrator for various types of commercial off-the-shelf operating systems. Restricting privileged accounts to specific personnel or roles prevents day-to-day users from accessing privileged information or privileged functions. Organizations may differentiate in the application of restricting privileged accounts between allowed privileges for local accounts and for domain accounts provided that they retain the ability to control system configurations for key parameters and as otherwise necessary to sufficiently mitigate risk.
Assessment Objective
privileged accounts on the system are restricted to {{ insert: param, ac-06.05_odp }}.
Access control policy
procedures addressing least privilege
list of system-generated privileged accounts
list of system administration personnel
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel with responsibilities for defining least privileges necessary to accomplish specified tasks
organizational personnel with information security responsibilities
system/network administrators
Mechanisms implementing least privilege functions