5. Privileged, and orphaned or dormant
The same gap on an account with administrative rights: nobody answers for the widest access in the list, or it sits unused with its rights intact.
The rule it applies
The account is privileged (its privileged column reads yes, its member-of column names an administrative group, or it is an administrator, break-glass or built-in administrator account) and it carries finding 1, 2, 3 or 4.
A question for the reviewer
Who holds these rights today, and do they still need them?
Clauses
6 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| ISO/IEC 27001 | ISO/IEC 27001 A.8.2 Privileged access rights | every account type |
| CIS Controls | CIS Controls 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-6 Least Privilege | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-6(5) Least privilege: Privileged Accounts | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-2(7) Account management: Privileged User Accounts | every account type |
| SOC 2 | SOC 2 CC6.3 Role-based access, least privilege and segregation of duties | every account type |
The first clause, set out
ISO/IEC 27001 A.8.2Privileged access rightsThe granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2.