Privileged access: the clause the question tests
Who holds administrator rights, how those rights are granted, and how their use is watched.
How the customer usually asks it
example"How is privileged or administrator access restricted and monitored?"
Anchor clauses
3 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 8.2 Privileged access rights |
| SIG (Shared Assessments) | domain H Access Control |
| NIST Cybersecurity Framework 2.0 | PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The list of privileged accounts with owners, how privileged sessions are granted and logged, and the last review of that list.
The clauses, with what an assessor asks for
ISO 27001 8.2 Privileged access rightsRestrict and manage the allocation and use of privileged access.
Where answers usually fall short: Outdated privileged account inventory; Missing or informal approval documentation
Source: ISO/IEC 27001:2022
SIG domain H Access ControlWhat it asks for, in one line (the standard's own text is not quoted here):
Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.
Where answers usually fall short: Privileged accounts shared; User reviews completed without manager attestation
Source: SIG (Shared Assessments)
NIST CSF PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of dutiesAccess permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Where answers usually fall short: Standing privileges still common; Access reviews rubber stamped
Source: NIST Cybersecurity Framework 2.0