id: "AC-06(08)" title: "Privilege Levels for Code Execution" family: "AC" family_name: "Access Control" sort_id: "ac-06.08" priority: "P1" implementation_level: "system" parent: "AC-06" enhancement: True
Statement
Prevent the following software from executing at higher privilege levels than users executing the software: {{ insert: param, ac-06.08_odp }}.
Guidance
In certain situations, software applications or programs need to execute with elevated privileges to perform required functions. However, depending on the software functionality and configuration, if the privileges required for execution are at a higher level than the privileges assigned to organizational users invoking such applications or programs, those users may indirectly be provided with greater privileges than assigned.
Assessment Objective
{{ insert: param, ac-06.08_odp }} is prevented from executing at higher privilege levels than users executing the software.
Access control policy
procedures addressing least privilege
list of software that should not execute at higher privilege levels than users executing software
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel with responsibilities for defining least privileges necessary to accomplish specified tasks
organizational personnel with information security responsibilities
system/network administrators
system developers
Mechanisms implementing least privilege functions for software execution