id: "AC-06(07)" title: "Review of User Privileges" family: "AC" family_name: "Access Control" sort_id: "ac-06.07" priority: "P1" implementation_level: "organization" parent: "AC-06" enhancement: True
Review {{ insert: param, ac-06.07_odp.01 }} the privileges assigned to {{ insert: param, ac-06.07_odp.02 }} to validate the need for such privileges; and
Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs.
Guidance
The need for certain assigned user privileges may change over time to reflect changes in organizational mission and business functions, environments of operation, technologies, or threats. A periodic review of assigned user privileges is necessary to determine if the rationale for assigning such privileges remains valid. If the need cannot be revalidated, organizations take appropriate corrective actions.
Assessment Objective: privileges assigned to {{ insert: param, ac-06.07_odp.02 }} are reviewed {{ insert: param, ac-06.07_odp.01 }} to validate the need for such privileges;
Assessment Objective: privileges are reassigned or removed, if necessary, to correctly reflect organizational mission and business needs.
Access control policy
procedures addressing least privilege
list of system-generated roles or classes of users and assigned privileges
system design documentation
system configuration settings and associated documentation
validation reviews of privileges assigned to roles or classes or users
records of privilege removals or reassignments for roles or classes of users
system audit records
system security plan
other relevant documents or records
Organizational personnel with responsibilities for reviewing least privileges necessary to accomplish specified tasks
organizational personnel with information security responsibilities
system/network administrators
Mechanisms implementing review of user privileges