AC.L2-3.1.7[c]: Enforce Privileged Account Use in Your Access Procedures

Enforcing Privileged Account Use Through Access Procedures

This objective verifies that documented access provisioning and user management procedures ensure privileged functions are performed only by designated privileged accounts. Review procedures to confirm they clearly assign privileged functions, prevent general-purpose accounts from gaining administrative permissions, and define how and when privileged accounts should be used during onboarding, role changes, and other lifecycle events. For broader context on CUI compliance requirements, ensure procedures align with defined privilege boundaries and access criteria.

Why Procedures Matter for Privileged Access Control

Policies articulate intent, but procedures operationalize control. If provisioning and change management processes do not require privilege validation, users may receive elevated access without oversight, and audit logs may not accurately reflect authorized privilege assignments. Clear, enforceable procedures reduce the risk of unauthorized access and support consistent application of controls during assessment.

Key Implementation Actions

Document privilege validation steps

Update access provisioning and user management procedures to include steps that verify whether privileged function requirements are met before granting elevated access. These steps should map roles to required permissions and include approval checkpoints where appropriate.

Enforce the use of designated privileged accounts

Require that all administrative and privileged functions are executed through accounts explicitly designated for such use. Standard user accounts should not be permitted to perform privileged actions, and procedures should reflect this separation.

Include revocation and downgrade processes

Ensure procedures define how privileged access is revoked or downgraded when no longer needed, such as when roles change or personnel leave the organization. This supports auditability and minimizes residual privileged access.

Typical Evidence for Assessment

  • Written procedures for provisioning and managing privileged accounts
  • Workflow documentation or ticketing records showing privileged access requests and approvals
  • System screenshots showing restricted privileges assigned via identity/access management tools
  • Logs or reports demonstrating approved privilege elevations and deprovisioning activities

Common Gaps to Address

  • Procedures do not differentiate between privileged and non-privileged access
  • Administrative staff use the same account for privileged and standard tasks
  • No verification or approval steps are incorporated before granting privileged access

Implementation Checklist

Action Description Evidence to Collect Review Frequency
Privilege assignment steps Procedures include criteria and approval for privileged access Procedural document with defined steps and roles Annual and on role changes
Privileged vs non-privileged separation Procedures enforce distinct use of privileged accounts Provisioning workflow examples showing separation Quarterly
Revocation and downgrade Procedures define how privileges are removed when no longer required Records of privilege revocations As changes occur
Approval checkpoints Approval steps exist for elevated access Ticketing or approval logs Ongoing

FAQ

What does AC.L2-3.1.7[c] require?

It requires that access provisioning procedures enforce the use of privileged accounts for administrative functions and ensure general accounts cannot gain elevated permissions.

Which artifacts support assessment evidence?

Written procedures, workflow records with privileged access approvals, system screenshots of restricted access, and logs of privilege changes are typical evidence.

Why is privilege separation important in procedures?

Because clear, enforced procedures prevent unauthorized elevation of access and ensure audit logs accurately reflect approved privilege assignments.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.