id: "AC-06(10)" title: "Prohibit Non-privileged Users from Executing Privileged Functions" family: "AC" family_name: "Access Control" sort_id: "ac-06.10" priority: "P1" implementation_level: "system" parent: "AC-06" enhancement: True
Statement
Prevent non-privileged users from executing privileged functions.
Guidance
Privileged functions include disabling, circumventing, or altering implemented security or privacy controls, establishing system accounts, performing system integrity checks, and administering cryptographic key management activities. Non-privileged users are individuals who do not possess appropriate authorizations. Privileged functions that require protection from non-privileged users include circumventing intrusion detection and prevention mechanisms or malicious code protection mechanisms. Preventing non-privileged users from executing privileged functions is enforced by AC-3.
Assessment Objective
non-privileged users are prevented from executing privileged functions.
Access control policy
procedures addressing least privilege
system design documentation
system configuration settings and associated documentation
list of privileged functions and associated user account assignments
system audit records
system security plan
other relevant documents or records
Organizational personnel with responsibilities for defining least privileges necessary to accomplish specified tasks
organizational personnel with information security responsibilities
system developers
Mechanisms implementing least privilege functions for non-privileged users