Administrator or privileged person account
The person it belongs to, as their second account kept only for administration; it is reviewed with their privileges.
Who should own an administrator or privileged person account, and which ISO/IEC 27001, SOC 2 and PCI DSS clauses apply?
The clauses the checker cites on an administrator or privileged person account: ISO/IEC 27001 A.8.2, ISO/IEC 27001 A.8.5 and SOC 2 CC6.3. Every clause it cites, across the seven regimes, is in the table below.
How the checker reads it
- It is a user account people sign in with: PCI DSS reads it under the user-account periods (8.2.6, 7.2.4, 8.3.9), never under 8.6.
- Its owner is its holder: the owner column, or the display name, or the account name itself, matched against the staff list.
- The type comes from your type column; when that is blank the checker reads the account name and labels the type assumed from the name, and any finding resting on it is read as a question by the reviewer.
Findings that can apply
7 of 14- 1. A leaver's own account is still enabled: Was this account disabled on the day the person left, and if not, what has it done since?
- 4. Dormant for more than the threshold: Is this account still needed, and if so by whom?
- 5. Privileged, and orphaned or dormant: Who holds these rights today, and do they still need them?
- 6. Password or key not changed within the period, or never: When was this credential last changed, and who knows it?
- 8. Credential stored in code, a config file or a script: Can this credential move into a vault, and who has read the file it sits in?
- 10. Not reviewed within the interval: Who reviews this account, and when is the next review due?
- 12. Created with no approval recorded: Where is the request and the approval for this account?
Clauses
8 cited| Regime | Clause |
|---|---|
| ISO/IEC 27001 | ISO/IEC 27001 A.8.2 Privileged access rights |
| ISO/IEC 27001 | ISO/IEC 27001 A.8.5 Secure authentication |
| SOC 2 | SOC 2 CC6.3 Role-based access, least privilege and segregation of duties |
| NIST SP 800-53 | NIST SP 800-53 AC-2(7) Account management: Privileged User Accounts |
| NIST SP 800-53 | NIST SP 800-53 AC-6(5) Least privilege: Privileged Accounts |
| CIS Controls | CIS Controls 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts |
| CIS Controls | CIS Controls 6.5 Require MFA for Administrative Access |
| NIS2 | NIS2 Art. 21(2)(j) Multi-factor or continuous authentication, secured communications and secured emergency communications |
The first clause, set out
ISO/IEC 27001 A.8.2Privileged access rightsThe granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2.
A line that reads as this type
the type column left blank, invented valuesadm-e1042 | | directory | | yes