Requests for privileged access to systems, applications and data repositories are validated when first requested. Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access. Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services. Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties. Privileged users use separate privileged and unprivileged operating environments. Unprivileged user accounts cannot logon to privileged operating environments. Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
ACSC Essential Eight ADMIN-ML1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ACSC Essential Eight your existing evidence covers. Hold FedRAMP Moderate and 18 of 24 ACSC Essential Eight controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the FedRAMP Moderate pair alone.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.