ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13)

ANSSI Guide d'hygiene informatique (42 mesures, v2.0) ANSSI-HYG-08: Identify Each Person by Name and Separate User and Administrator Roles

Give each person accessing the system a nominative account, and keep user roles separate from administrator roles so that administration is not performed from an ordinary user account.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 69 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CMMC 2.0 · 6 controls

  • ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy
  • ASBv3-GS-6 Define and implement identity and privileged access strategy
  • ASBv3-PA-6 Use privileged access workstations
  • IM-1 Use centralized identity and authentication system
  • PA-1 Separate and limit highly privileged/administrative users

C5 (Germany) · 4 controls

FedRAMP High · 4 controls

  • AC-2 Account Management
  • AC-5 Separation of Duties
  • AC-6(2) Non-Privileged Access for Nonsecurity Functions
  • IA-2 Identification and Authentication (Organizational Users)

FedRAMP Moderate · 4 controls

  • AC-2 Account Management
  • AC-5 Separation of Duties
  • AC-6(2) Non-Privileged Access for Nonsecurity Functions
  • IA-2 Identification and Authentication (Organizational Users)

ISO 27001:2022 · 4 controls

  • 5.15 Access control
  • 5.16 Identity management
  • 5.3 Segregation of duties
  • 8.2 Privileged access rights

ISO 27002:2022 · 4 controls

  • 5.15 Access control
  • 5.16 Identity management
  • 5.3 Segregation of duties
  • 8.2 Privileged access rights

NIST SP 800-171 Rev 3 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 8.2.1 8.2.1 Unique ID assigned to every user
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.4.1 8.4.1 MFA for non-console administrative CDE access

CIS Controls v8 · 3 controls

  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts

SOC 2 · 3 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties

UK Cyber Essentials · 3 controls

  • CE-AC.2 Authenticate Users Before Granting Access
  • CE-AC.5 Separate Admin Accounts for Administrative Activities
  • CE-SC.4 Authenticate Users Before Access
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-21 Disable local administrator accounts (Excellent)

HIPAA Security Rule · 2 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13)

You are reading one control. How much of ANSSI Guide d'hygiene informatique (42 mesures, v2.0) have you already done?

ANSSI Guide d'hygiene informatique (42 mesures, v2.0) ANSSI-HYG-08 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ANSSI Guide d'hygiene informatique (42 mesures, v2.0) your existing evidence covers. Hold FedRAMP Moderate and 35 of 42 ANSSI Guide d'hygiene informatique (42 mesures, v2.0) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 69 it maps to, and the evidence behind each claim, over MCP and REST.