The granting and use of privileged access rights are to be limited and managed. Purpose: limit privileged access to the people, software components and services that are authorized for it. Guidance: allocate privileged rights through an authorization process under the access control policy (5.15), considering: identifying who needs privileged access for each system or process, whether an operating system, a database platform or an application; granting it as needed and per event, only to people competent to carry out the privileged activity and at the minimum their role requires; keeping an authorization process (who may approve, and no privilege before approval) and a record of all privileges granted; defining and applying expiry of privileged rights; making users aware of their privileges and of when they are operating in privileged mode, using dedicated identities, interface settings or even separate equipment; stronger authentication than for normal access, possibly re-authentication or step-up before privileged work; reviewing privileged users regularly and after organizational change to confirm their duties, role and competence still justify it (5.18); rules to avoid generic administrator accounts such as root where systems allow, and protecting their credentials (5.17); temporary elevation only for the window needed to carry out an approved change or activity instead of standing privilege, often called break glass and frequently automated by privileged access management tools; logging all privileged access for audit; never sharing privileged identities among several people, giving each person a separate identity, though identities may be grouped to simplify management; and using privileged identities only for administration, never for everyday tasks like email or browsing, for which a separate normal identity is used. Other information: privileged rights let an identity, role or process do what ordinary users or processes cannot, as system administrators typically need; abuse of administrator powers able to bypass system or application safeguards is a leading cause of failures and breaches; ISO/IEC 29146 gives further guidance.
This control maps to 132 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
E8-ADMIN-ISM-0445 Restrict administrative privileges (ISM-0445): Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access
E8-ADMIN-ISM-1175 Restrict administrative privileges (ISM-1175): Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services
E8-ADMIN-ISM-1380 Restrict administrative privileges (ISM-1380): Privileged users use separate privileged and unprivileged operating environments
E8-ADMIN-ISM-1387 Restrict administrative privileges (ISM-1387): Administrative activities are conducted through jump servers
E8-ADMIN-ISM-1508 Restrict administrative privileges (ISM-1508): Privileged access to systems, applications and data repositories is limited to only what is required for users and services to undertake their duties
E8-ADMIN-ISM-1649 Restrict administrative privileges (ISM-1649): Just-in-time administration is used for administering systems and applications
E8-ADMIN-ISM-1687 Restrict administrative privileges (ISM-1687): Privileged operating environments are not virtualised within unprivileged operating environments
E8-ADMIN-ISM-1688 Restrict administrative privileges (ISM-1688): Unprivileged user accounts cannot logon to privileged operating environments
E8-ADMIN-ISM-1689 Restrict administrative privileges (ISM-1689): Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments
E8-ADMIN-ISM-1883 Restrict administrative privileges (ISM-1883): Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties
E8-ADMIN-ISM-1898 Restrict administrative privileges (ISM-1898): Secure Admin Workstations are used in the performance of administrative activities
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.