id: "AC-06(09)" title: "Log Use of Privileged Functions" family: "AC" family_name: "Access Control" sort_id: "ac-06.09" priority: "P1" implementation_level: "system" parent: "AC-06" enhancement: True


Statement

Log the execution of privileged functions.

Guidance

The misuse of privileged functions, either intentionally or unintentionally by authorized users or by unauthorized external entities that have compromised system accounts, is a serious and ongoing concern and can have significant adverse impacts on organizations. Logging and analyzing the use of privileged functions is one way to detect such misuse and, in doing so, help mitigate the risk from insider threats and the advanced persistent threat.

Assessment Objective

the execution of privileged functions is logged.

Access control policy

procedures addressing least privilege

system design documentation

system configuration settings and associated documentation

list of privileged functions to be audited

list of audited events

system audit records

system security plan

other relevant documents or records

Organizational personnel with responsibilities for reviewing least privileges necessary to accomplish specified tasks

organizational personnel with information security responsibilities

system/network administrators

system developers

Mechanisms auditing the execution of least privilege functions