id: "AC-06(06)" title: "Privileged Access by Non-organizational Users" family: "AC" family_name: "Access Control" sort_id: "ac-06.06" priority: "P1" implementation_level: "organization" parent: "AC-06" enhancement: True


Statement

Prohibit privileged access to the system by non-organizational users.

Guidance

An organizational user is an employee or an individual considered by the organization to have the equivalent status of an employee. Organizational users include contractors, guest researchers, or individuals detailed from other organizations. A non-organizational user is a user who is not an organizational user. Policies and procedures for granting equivalent status of employees to individuals include a need-to-know, citizenship, and the relationship to the organization.

Assessment Objective

privileged access to the system by non-organizational users is prohibited.

Access control policy

procedures addressing least privilege

list of system-generated privileged accounts

list of non-organizational users

system configuration settings and associated documentation

audit records

system security plan

other relevant documents or records

Organizational personnel with responsibilities for defining least privileges necessary to accomplish specified tasks

organizational personnel with information security responsibilities

system/network administrators

Mechanisms prohibiting privileged access to the system