Frameworks / ASD Strategies to Mitigate Cyber Security Incidents / ASD37-18 ASD Strategies to Mitigate Cyber Security Incidents
Limiting the Extent of Cyber Security Incidents
ASD Strategies to Mitigate Cyber Security Incidents ASD37-18: Restrict administrative privileges (Essential) Restrict administrative privileges to operating systems and applications based on user duties. Regularly revalidate the need for privileges. Don't use privileged accounts for reading email and web browsing.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 179 controls across 95 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work CIS-3.3 Configure Data Access Control Lists CIS-5.1 Establish and Maintain an Inventory of Accounts CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts CIS-6.1 Establish an Access Granting Process CIS-6.8 Define and Maintain Role-Based Access Control ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need AC-3 Access Enforcement AC-6 Least Privilege AC-6(2) Non-Privileged Access for Nonsecurity Functions AC-6(5) Privileged Accounts AC-6(7) Review of User Privileges AC-3 Access Enforcement AC-6 Least Privilege AC-6(2) Non-Privileged Access for Nonsecurity Functions AC-6(5) Privileged Accounts AC-6(7) Review of User Privileges ASBv3-PA-4 Review and reconcile user access regularly ASBv3-PA-6 Use privileged access workstations ASBv3-PA-7 Follow just enough administration (least privilege) principle PA-1 Separate and limit highly privileged/administrative users E8-ADMIN-ML1 Restrict Administrative Privileges (ML1) E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) E8-ADMIN-ML3 Restrict Administrative Privileges (ML3) 5.18 Access rights 8.18 Use of privileged utility programs 8.2 Privileged access rights 5.18 Access rights 8.18 Use of privileged utility programs 8.2 Privileged access rights NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) 7.2.2 7.2.2 User access assigned by job function and least privilege 7.2.3 7.2.3 Privileges approved by authorized personnel 7.2.4 7.2.4 User accounts and privileges reviewed every six months SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties CE-AC.4 Privileged Account Approval and Tracking CE-AC.5 Separate Admin Accounts for Administrative Activities CE-AC.6 Periodic Review of Privileged Access AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management ITAR-Part123-125-ExportLicensing-DSP-5-DSP-73-DSP-61-MLA-TAA-Classified-Information-Routed ITAR Parts 123-125 Export Licensing - DSP-5 Permanent Export + DSP-73 Temporary Export + DSP-61 Temporary Import + DSP-83 + Manufacturing License Agreements (MLA) + Technical Assistance Agreements (TAA) + Classified Information + Routed Export Transactions ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) SSAE18-CC6.2 CC6.2 - New User Registration and Authorization SSAE18-SOC1-06 Transaction Processing Controls SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements BSI-02 Access enforcement and least privilege BE-CF-02 Access enforcement and least privilege DSO-3 Data Access Management Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h)) CAT-IRP-4 Organizational characteristics FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition) ICAO-ANX17-Chap4-SpecialCategories-Weapons-InFlightSecurity-CockpitDoor ICAO Annex 17 Chapter 4 - Special Categories of Passengers + Weapons + In-Flight Security Officers + Flight Crew Compartment Door 62351-8 Role-based access control (RBAC) ISO-19650-2-5.7 Information model delivery ISO27799-01 ePHI access controls and authorization 27011-8.1 User Endpoint Devices ISO27043-14 Privileged access management 27400-6.1 Secure Device Design ISO21434-14 Privileged access management MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NIST190-08 Privileged access in cloud environments NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PTESPHASE-2 Intelligence Gathering (OSINT) SHAREASSESS-2 Access Control, Identity, Authentication SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule CISABD-1 Take Ownership of Customer Security Outcomes SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain SIGSTORE-2 Transparency Log (Rekor) and Verification ISMSP-AC-01 Access Control Policy TSAPIPE-2 OT/IT Network Segmentation and Access Control UK-TSA-NET-02 Access Control and Authentication ACE-CR-4 Cargo Release Authorization UGA-10 Sensitive Personal Data Prohibition Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Limiting the Extent of Cyber Security Incidents You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done? ASD Strategies to Mitigate Cyber Security Incidents ASD37-18 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 179 it maps to, and the evidence behind each claim, over MCP and REST.