id: "AC-06(10)" title: "Prohibit Non-privileged Users from Executing Privileged Functions" family: "AC" family_name: "Access Control" sort_id: "ac-06.10" priority: "P1" implementation_level: "system" parent: "AC-06" enhancement: True


Statement

Prevent non-privileged users from executing privileged functions.

Guidance

Privileged functions include disabling, circumventing, or altering implemented security or privacy controls, establishing system accounts, performing system integrity checks, and administering cryptographic key management activities. Non-privileged users are individuals who do not possess appropriate authorizations. Privileged functions that require protection from non-privileged users include circumventing intrusion detection and prevention mechanisms or malicious code protection mechanisms. Preventing non-privileged users from executing privileged functions is enforced by AC-3.

Assessment Objective

non-privileged users are prevented from executing privileged functions.

Access control policy

procedures addressing least privilege

system design documentation

system configuration settings and associated documentation

list of privileged functions and associated user account assignments

system audit records

system security plan

other relevant documents or records

Organizational personnel with responsibilities for defining least privileges necessary to accomplish specified tasks

organizational personnel with information security responsibilities

system developers

Mechanisms implementing least privilege functions for non-privileged users