id: "AC-06(09)" title: "Log Use of Privileged Functions" family: "AC" family_name: "Access Control" sort_id: "ac-06.09" priority: "P1" implementation_level: "system" parent: "AC-06" enhancement: True
Statement
Log the execution of privileged functions.
Guidance
The misuse of privileged functions, either intentionally or unintentionally by authorized users or by unauthorized external entities that have compromised system accounts, is a serious and ongoing concern and can have significant adverse impacts on organizations. Logging and analyzing the use of privileged functions is one way to detect such misuse and, in doing so, help mitigate the risk from insider threats and the advanced persistent threat.
Assessment Objective
the execution of privileged functions is logged.
Access control policy
procedures addressing least privilege
system design documentation
system configuration settings and associated documentation
list of privileged functions to be audited
list of audited events
system audit records
system security plan
other relevant documents or records
Organizational personnel with responsibilities for reviewing least privileges necessary to accomplish specified tasks
organizational personnel with information security responsibilities
system/network administrators
system developers
Mechanisms auditing the execution of least privilege functions