ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.2: Privileged access rights

The granting and use of privileged access rights are to be limited and managed. Purpose: limit privileged access to the people, software components and services that are authorized for it. Guidance: allocate privileged rights through an authorization process under the access control policy (5.15), considering: identifying who needs privileged access for each system or process, whether an operating system, a database platform or an application; granting it as needed and per event, only to people competent to carry out the privileged activity and at the minimum their role requires; keeping an authorization process (who may approve, and no privilege before approval) and a record of all privileges granted; defining and applying expiry of privileged rights; making users aware of their privileges and of when they are operating in privileged mode, using dedicated identities, interface settings or even separate equipment; stronger authentication than for normal access, possibly re-authentication or step-up before privileged work; reviewing privileged users regularly and after organizational change to confirm their duties, role and competence still justify it (5.18); rules to avoid generic administrator accounts such as root where systems allow, and protecting their credentials (5.17); temporary elevation only for the window needed to carry out an approved change or activity instead of standing privilege, often called break glass and frequently automated by privileged access management tools; logging all privileged access for audit; never sharing privileged identities among several people, giving each person a separate identity, though identities may be grouped to simplify management; and using privileged identities only for administration, never for everyday tasks like email or browsing, for which a separate normal identity is used. Other information: privileged rights let an identity, role or process do what ordinary users or processes cannot, as system administrators typically need; abuse of administrator powers able to bypass system or application safeguards is a leading cause of failures and breaches; ISO/IEC 29146 gives further guidance.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 132 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ACSC Essential Eight · 14 controls

  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • E8-ADMIN-ML3 Restrict Administrative Privileges (ML3)
  • E8-ADMIN-ISM-0445 Restrict administrative privileges (ISM-0445): Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access
  • E8-ADMIN-ISM-1175 Restrict administrative privileges (ISM-1175): Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services
  • E8-ADMIN-ISM-1380 Restrict administrative privileges (ISM-1380): Privileged users use separate privileged and unprivileged operating environments
  • E8-ADMIN-ISM-1387 Restrict administrative privileges (ISM-1387): Administrative activities are conducted through jump servers
  • E8-ADMIN-ISM-1508 Restrict administrative privileges (ISM-1508): Privileged access to systems, applications and data repositories is limited to only what is required for users and services to undertake their duties
  • E8-ADMIN-ISM-1649 Restrict administrative privileges (ISM-1649): Just-in-time administration is used for administering systems and applications
  • E8-ADMIN-ISM-1687 Restrict administrative privileges (ISM-1687): Privileged operating environments are not virtualised within unprivileged operating environments
  • E8-ADMIN-ISM-1688 Restrict administrative privileges (ISM-1688): Unprivileged user accounts cannot logon to privileged operating environments
  • E8-ADMIN-ISM-1689 Restrict administrative privileges (ISM-1689): Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments
  • E8-ADMIN-ISM-1883 Restrict administrative privileges (ISM-1883): Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties
  • E8-ADMIN-ISM-1898 Restrict administrative privileges (ISM-1898): Secure Admin Workstations are used in the performance of administrative activities

FedRAMP High · 12 controls

  • AC-17(4) Privileged Commands and Access
  • AC-2 Account Management
  • AC-2(7) Privileged User Accounts
  • AC-6 Least Privilege
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(10) Prohibit Non-Privileged Users from Executing Privileged Functions
  • AC-6(2) Non-Privileged Access for Nonsecurity Functions
  • AC-6(5) Privileged Accounts
  • AU-9(4) Access by Subset of Privileged Users
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))
  • RA-5(5) Privileged Access
  • SC-2 Separation of System and User Functionality

FedRAMP Moderate · 12 controls

  • AC-17(4) Privileged Commands and Access
  • AC-2 Account Management
  • AC-2(7) Privileged User Accounts
  • AC-6 Least Privilege
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(10) Prohibit Non-Privileged Users from Executing Privileged Functions
  • AC-6(2) Non-Privileged Access for Nonsecurity Functions
  • AC-6(5) Privileged Accounts
  • AU-9(4) Access by Subset of Privileged Users
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))
  • RA-5(5) Privileged Access
  • SC-2 Separation of System and User Functionality

PCI DSS 4.0 · 11 controls

  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 3.7.6 3.7.6 Split knowledge and dual control for manual key operations
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 8.4.1 8.4.1 MFA for non-console administrative CDE access
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 8.6.1 8.6.1 Interactive use of system accounts controlled
  • ASBv3-AM-4 Limit access to asset management
  • ASBv3-GS-6 Define and implement identity and privileged access strategy
  • ASBv3-IM-2 Protect identity and authentication systems
  • ASBv3-PA-4 Review and reconcile user access regularly
  • ASBv3-PA-6 Use privileged access workstations
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • PA-1 Separate and limit highly privileged/administrative users
  • PA-2 Avoid standing access for user accounts and permissions

CMMC 2.0 · 8 controls

  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ANSSI-HYG-13 Prefer Strong Authentication Where Possible
  • ANSSI-HYG-27 Prohibit Internet Access from Administration Workstations and Servers
  • ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need
  • ISM-0445 Dedicated privileged user accounts
  • ISM-0629 Administering shared gateway components
  • ISM-1507 Validating privileged access requests
  • ISM-1508 Least privilege for privileged access
  • ISM-1647 Disabling privileged access after 12 months

C5 (Germany) · 4 controls

CIS Controls v8 · 4 controls

  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • CIS-6.5 Require MFA for Administrative Access

NIST SP 800-53 Rev 5 · 4 controls

UK Cyber Essentials · 4 controls

  • CE-AC.4 Privileged Account Approval and Tracking
  • CE-AC.5 Separate Admin Accounts for Administrative Activities
  • CE-AC.6 Periodic Review of Privileged Access
  • CE-AC.7 MFA for Administrative Accounts

MTCS (Singapore) · 3 controls

  • 22.10 Session management
  • 22.13 Third party administrative access
  • 22.2 Privilege account creation

NIST SP 800-171 Rev 3 · 3 controls

  • 03.01.06 Least Privilege - Privileged Accounts
  • 03.01.07 Least Privilege - Privileged Functions
  • 03.05.03 Multi-Factor Authentication

SOC 2 · 3 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-21 Disable local administrator accounts (Excellent)

HIPAA Security Rule · 2 controls

ISO 27701:2019 · 2 controls

  • 6.6 Access control
  • 6.6.2 User access management

NIS2 Directive · 2 controls

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training
  • Art.21.2.i Human resources security, access control policies and asset management
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented

NIST SP 800-172 · 2 controls

  • 3.1.1e Dual Authorization for Sensitive System Operations
  • 3.5.3e Prohibit Connection of Unknown or Unverified System Components

NIST SP 800-66 Rev 2 · 2 controls

NY DFS 23 NYCRR 500 · 2 controls

  • PROC.HOSTED Isolate hosted client instances and limit DSP access to support with consent
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

DORA · 1 control

ETSI EN 303 645 · 1 control

  • Provision 5.5-5 Security-relevant configuration over the network only after authentication

ISO 27001:2022 · 1 control

  • 8.2 Privileged access rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 132 it maps to, and the evidence behind each claim, over MCP and REST.