PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AC-6 — Least Privilege

Framework: NIST SP 800-53 Rev.5 AC-6 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine For a sample of roles/users, confirm assigned entitlements are limited to the minimum necessary for the job function, with no broad or default-wide privileges beyond documented need.
Examine Obtain the privileged-account inventory and confirm administrators perform privileged work using separate, dedicated administrative accounts distinct from their standard day-to-day user accounts (CIS v8 5.4).
Test Confirm there are no standing shared or generic administrator credentials; verify privileged access is individually attributable and, where implemented, granted just-in-time/time-bound rather than permanently standing.
Examine Confirm privileged entitlements are recertified/reviewed at the defined frequency, with dated sign-off, and that removed or reduced privileges were actioned.
Test Using a non-privileged test account, attempt to execute a privileged or security function (e.g., change a security setting, install software, access an admin console) and confirm the action is denied.
Examine Confirm privileged/admin accounts are restricted from performing non-privileged general functions (email, web browsing, arbitrary internet access) so day-to-day activity uses a separate lower-privilege account.
Examine Confirm the use of privileged functions and access to security functions is audit-logged and the logs are retained and reviewed (AC-6(9); CIS v8 8.x).