Enforcing Privileged Account Use Through Access Procedures
This objective verifies that documented access provisioning and user management procedures ensure privileged functions are performed only by designated privileged accounts. Review procedures to confirm they clearly assign privileged functions, prevent general-purpose accounts from gaining administrative permissions, and define how and when privileged accounts should be used during onboarding, role changes, and other lifecycle events. For broader context on CUI compliance requirements, ensure procedures align with defined privilege boundaries and access criteria.
Why Procedures Matter for Privileged Access Control
Policies articulate intent, but procedures operationalize control. If provisioning and change management processes do not require privilege validation, users may receive elevated access without oversight, and audit logs may not accurately reflect authorized privilege assignments. Clear, enforceable procedures reduce the risk of unauthorized access and support consistent application of controls during assessment.
Key Implementation Actions
Document privilege validation steps
Update access provisioning and user management procedures to include steps that verify whether privileged function requirements are met before granting elevated access. These steps should map roles to required permissions and include approval checkpoints where appropriate.
Enforce the use of designated privileged accounts
Require that all administrative and privileged functions are executed through accounts explicitly designated for such use. Standard user accounts should not be permitted to perform privileged actions, and procedures should reflect this separation.
Include revocation and downgrade processes
Ensure procedures define how privileged access is revoked or downgraded when no longer needed, such as when roles change or personnel leave the organization. This supports auditability and minimizes residual privileged access.
Typical Evidence for Assessment
- Written procedures for provisioning and managing privileged accounts
- Workflow documentation or ticketing records showing privileged access requests and approvals
- System screenshots showing restricted privileges assigned via identity/access management tools
- Logs or reports demonstrating approved privilege elevations and deprovisioning activities
Common Gaps to Address
- Procedures do not differentiate between privileged and non-privileged access
- Administrative staff use the same account for privileged and standard tasks
- No verification or approval steps are incorporated before granting privileged access
Implementation Checklist
| Action | Description | Evidence to Collect | Review Frequency |
|---|---|---|---|
| Privilege assignment steps | Procedures include criteria and approval for privileged access | Procedural document with defined steps and roles | Annual and on role changes |
| Privileged vs non-privileged separation | Procedures enforce distinct use of privileged accounts | Provisioning workflow examples showing separation | Quarterly |
| Revocation and downgrade | Procedures define how privileges are removed when no longer required | Records of privilege revocations | As changes occur |
| Approval checkpoints | Approval steps exist for elevated access | Ticketing or approval logs | Ongoing |
FAQ
What does AC.L2-3.1.7[c] require?
It requires that access provisioning procedures enforce the use of privileged accounts for administrative functions and ensure general accounts cannot gain elevated permissions.
Which artifacts support assessment evidence?
Written procedures, workflow records with privileged access approvals, system screenshots of restricted access, and logs of privilege changes are typical evidence.
Why is privilege separation important in procedures?
Because clear, enforced procedures prevent unauthorized elevation of access and ensure audit logs accurately reflect approved privilege assignments.