Security Questionnaire Mapper
Access and identity ยท question family

Privileged access: the clause the question tests

Who holds administrator rights, how those rights are granted, and how their use is watched.

How the customer usually asks it

example

"How is privileged or administrator access restricted and monitored?"

Read this question

Anchor clauses

3 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20228.2 Privileged access rights
SIG (Shared Assessments)domain H Access Control
NIST Cybersecurity Framework 2.0PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The list of privileged accounts with owners, how privileged sessions are granted and logged, and the last review of that list.

The clauses, with what an assessor asks for

ISO 27001 8.2 Privileged access rights

Restrict and manage the allocation and use of privileged access.

Evidence an assessor expects: Privileged account inventory; Privileged access approval; Privileged access review; Privileged access logging
Where answers usually fall short: Outdated privileged account inventory; Missing or informal approval documentation
Source: ISO/IEC 27001:2022
SIG domain H Access Control

What it asks for, in one line (the standard's own text is not quoted here):

Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.

Evidence an assessor expects: Access management policy; User access review reports; Privileged access management tool logs; Joiner mover leaver workflows
Where answers usually fall short: Privileged accounts shared; User reviews completed without manager attestation
Source: SIG (Shared Assessments)
NIST CSF PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Evidence an assessor expects: Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records
Where answers usually fall short: Standing privileges still common; Access reviews rubber stamped
Source: NIST Cybersecurity Framework 2.0

Other families in access and identity