NIST SP 800-53 Revision 5.1 HIGH AC-6(2): Non-Privileged Access for Nonsecurity Functions
Require privileged users to use non-privileged accounts for nonsecurity functions.
What else in your programme already covers this
This control maps to 18 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
7.2.5 All application and system accounts and related access privileges are assigned and managed as follows: • Based on the least privileges necessary for the operability of the system or application. • Access is limited
8.6.1 If accounts used by systems or applications can be used for interactive login, they are managed as follows: • Interactive use is prevented unless needed for an exceptional circumstance. • Interactive use is limited