← Controls / AC

AC-06 Least Privilege

Access Control

Moderate High

Description

Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.

Supplemental Guidance

Organizations employ least privilege for specific duties and systems. The principle of least privilege is also applied to system processes, ensuring that the processes have access to systems and operate at privilege levels no higher than necessary to accomplish organizational missions or business functions. Organizations consider the creation of additional processes, roles, and accounts as necessary to achieve least privilege. Organizations apply least privilege to the development, implementation, and operation of organizational systems.

Enhancements (10)

What NIST adds to this control. Select one to read its statement.

AC-06(01) Authorize Access to Security Functions ModerateHigh

Authorize access for [Assignment: organization-defined individuals or roles] to: a. [Assignment: organization-defined security functions (deployed in hardware, software, and firmware)]; and b. [Assignment: organization-defined security-relevant information].

AC-06(02) Non-privileged Access for Nonsecurity Functions ModerateHigh

Require that users of system accounts (or roles) with access to [Assignment: organization-defined security functions or security-relevant information] use non-privileged accounts or roles, when accessing nonsecurity functions.

AC-06(03) Network Access to Privileged Commands High

Authorize network access to [Assignment: organization-defined privileged commands] only for [Assignment: organization-defined compelling operational needs] and document the rationale for such access in the security plan for the system.

AC-06(04) Separate Processing Domains

Provide separate processing domains to enable finer-grained allocation of user privileges.

AC-06(05) Privileged Accounts ModerateHigh

Restrict privileged accounts on the system to [Assignment: organization-defined personnel or roles].

AC-06(06) Privileged Access by Non-organizational Users

Prohibit privileged access to the system by non-organizational users.

AC-06(07) Review of User Privileges ModerateHigh

a. Review [Assignment: organization-defined frequency] the privileges assigned to [Assignment: organization-defined roles or classes of users] to validate the need for such privileges; and b. Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs.

AC-06(08) Privilege Levels for Code Execution

Prevent the following software from executing at higher privilege levels than users executing the software: [Assignment: organization-defined software].

AC-06(09) Log Use of Privileged Functions ModerateHigh

Log the execution of privileged functions.

AC-06(10) Prohibit Non-privileged Users from Executing Privileged Functions ModerateHigh

Prevent non-privileged users from executing privileged functions.

MITRE ATT&CK Techniques (270)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Initial Access 13 Execution 32 Persistence 81 Privilege Escalation 72 Defense Evasion 99 Credential Access 44 Discovery 6 Lateral Movement 18 Collection 11 Exfiltration 9 Impact 13
Show all 270 techniques grouped by tactic

Execution

Persistence

T1053 T1078 T1098 T1133 T1136 T1137 T1176 T1197 T1505 T1525 T1542 T1543 T1546 T1556 T1574 T1053.002 T1053.003 T1053.005 T1053.006 T1053.007 T1078.001 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.004 T1098.005 T1098.006 T1098.007 T1136.001 T1136.002 T1136.003 T1137.001 T1137.002 T1137.003 T1137.004 T1137.005 T1137.006 T1505.002 T1505.003 T1505.004 T1505.005 T1542.001 T1542.003 T1542.004 T1542.005 T1543.001 T1543.002 T1543.003 T1543.004 T1543.005 T1546.003 T1546.004 T1546.011 T1546.013 T1546.016 T1547.003 T1547.004 T1547.006 T1547.009 T1547.012 T1547.013 T1556.001 T1556.003 T1556.004 T1556.005 T1556.006 T1556.007 T1556.008 T1556.009 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.011 T1574.012 T1574.014

Privilege Escalation

T1053 T1055 T1068 T1078 T1098 T1134 T1484 T1543 T1546 T1548 T1574 T1611 T1053.002 T1053.003 T1053.005 T1053.006 T1053.007 T1055.001 T1055.002 T1055.003 T1055.004 T1055.005 T1055.008 T1055.009 T1055.011 T1055.012 T1055.013 T1055.014 T1078.001 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.004 T1098.005 T1098.006 T1098.007 T1134.001 T1134.002 T1134.003 T1134.005 T1543.001 T1543.002 T1543.003 T1543.004 T1543.005 T1546.003 T1546.004 T1546.011 T1546.013 T1546.016 T1547.003 T1547.004 T1547.006 T1547.009 T1547.012 T1547.013 T1548.002 T1548.003 T1548.005 T1548.006 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.011 T1574.012 T1574.014

Defense Evasion

T1036 T1055 T1070 T1078 T1112 T1134 T1197 T1211 T1218 T1222 T1484 T1542 T1548 T1550 T1553 T1556 T1562 T1574 T1578 T1599 T1601 T1610 T1612 T1647 T1036.003 T1036.005 T1055.001 T1055.002 T1055.003 T1055.004 T1055.005 T1055.008 T1055.009 T1055.011 T1055.012 T1055.013 T1055.014 T1070.001 T1070.002 T1070.003 T1070.007 T1070.008 T1070.009 T1078.001 T1078.002 T1078.003 T1078.004 T1134.001 T1134.002 T1134.003 T1134.005 T1218.007 T1218.015 T1222.001 T1222.002 T1542.001 T1542.003 T1542.004 T1542.005 T1548.002 T1548.003 T1548.005 T1548.006 T1550.002 T1550.003 T1553.003 T1553.006 T1556.001 T1556.003 T1556.004 T1556.005 T1556.006 T1556.007 T1556.008 T1556.009 T1562.001 T1562.002 T1562.004 T1562.006 T1562.007 T1562.008 T1562.009 T1562.012 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.011 T1574.012 T1574.014 T1578.001 T1578.002 T1578.003 T1578.005 T1599.001 T1601.001 T1601.002

Credential Access

Compliance Mappings

ISO 27001:2022

A.5.15A.5.18A.8.2A.8.3A.8.18

ISO 27002:2022

5.155.188.28.38.18

COBIT 2019

DSS05DSS06

CIS Controls v8

CIS 3.3CIS 3.14CIS 5CIS 5.4CIS 6CIS 6.1CIS 6.8CIS 12.8

NIST CSF 2.0

PR.AA-05

SOC 2 TSC

CC6.1CC6.1-POF7

PCI DSS v4.0.1

3.47.17.28.6

CSA CCM v4

IAM-04IAM-05IAM-08IAM-09IAM-10IAM-11IAM-16LOG-04

CSA AICM v1

IAM-04IAM-05IAM-08IAM-09IAM-10IAM-11IAM-16IAM-18IAM-19LOG-04MDS-07

FINOS CCC

CCC-C11CCC-C12

ISO 42001:2023

A.3.2A.9.2

IEC 62443

3-3 SR 1.33-3 SR 2.1

NIS2 Directive

Art. 21(2)(i)

MAS TRM

9

APRA CPS 234

Para 22-23

ASD Essential Eight

E8-5E8-5 ML1E8-5 ML2E8-5 ML3E8-8 ML3

BSI IT-Grundschutz

OPS.1.1.2ORP.4

ANSSI

Hygiene.14Hygiene.15Hygiene.16Hygiene.17SecNumCloud.10.3SecNumCloud.10.4

FINMA Circular 2023/1

IV.B.d(59)IV.B.d(60)IV.C(61)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(c)Art.5(1)(f)Art.25(2)Art.32(1)(b)

EU DORA

Art.9(4)(c)Art.9(4)(d)

BIO2

5.155.188.28.38.18

RBI CSF

Annex1.8ITGRCA.19

FISC Security Guidelines

FISC.T2

LGPD + BCB 4893

BCB.Art.3LGPD.Art.6LGPD.Art.46

HKMA TM-E-1

TME1.8.1TME1.8.2

MLPS 2.0

8.1.4.28.1.5.18.1.10.4

DNB Good Practice

DNB.7.1DNB.17.2

EU CRA

CRA.I.2d

SWIFT CSCF

SWIFT.1.2SWIFT.5.1SWIFT.6.3

SAMA CSF

3.1

NCA ECC

2-2

UAE IA

T9

CBB TM

TM-6

Qatar NIA

AC

CBUAE

CR-4

CBE CSF

CD-1CTO-1

SA JS2

JS2-7.1

CBN CSF

Part3.2Part9

BoG CISD

CISD-VIII

POPIA

s10s19

BoM CTRM

3.3

IOSCO Cyber Resilience

PROT-1

BCBS 239

Principle 11

CPMI-IOSCO PFMI

CG.PRPFMI.P17

FFIEC IS

II.C.7II.C.7(b)II.C.13(a)II.C.15II.C.15(a)II.C.15(b)II.C.18

NYDFS 500

500.6500.7

HIPAA Security Rule

§164.308(a)(3)(i)§164.308(a)(3)(ii)(A)§164.308(a)(3)(ii)(B)§164.308(a)(4)(i)§164.308(a)(4)(ii)(B)§164.308(a)(4)(ii)(C)§164.312(a)(1)§164.314(b)(2)

ECB CROE

CROE.2.3.1

EBA ICT Guidelines

3.4.2

SEBI CSCRF

PR.AA

BOT Cyber Resilience

Ch2.2

CMMC 2.0

AC

10 CFR 73.54

RG5.71-A-AC

TSA Pipeline SD

SD-2 Sec B

IEEE 1686-2022

5.1

DOE C2M2 v2.1

ACCESS

API 1164

Sec 6

AWIA

AWWA Sec 3

IAEA NSS 17-T

Sec 5.3

FIPS 140-3

FIPS 140-3 §7.4

TIBER-EU

TIBER.CONF

PCI HSM

1458

Common Criteria

CC Part 2 — FDPCC Part 2 — FMT

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.4

Lloyd's Minimum Standards

MS1.1MS5.1MS8.3

NAIC Insurance Data Security

4-access4-audit4B

PRA SS1/23

P2.4P3.3P3.6P4.4P-IT.1

FCA SYSC 13

SYSC 13.6.2SYSC 13.7.3

HITRUST CSF v11

01.a13.c13.e

FDA 21 CFR Part 11

§11.10(d)§11.10(g)

FDA Cybersecurity Guidance

SA-1SA-4

ISO 27799

9.19.39.5H.4

NHS DSPT

NDG-1.1NDG-4.1NDG-4.4

OWASP MASVS v2.1

MASVS-PRIVACY-1

CCSS v9.0

1.03.51.04.31.05.11.05.3

MiCA

Art.36(1)Art.40(1)Art.55(1)Art.63(1)Art.65(1)Art.67(1)Art.86(1)Art.92(1)Art.97(1)

Basel SCO60

SCO60.55SCO60.61SCO60.62SCO60.64SCO60.66SCO60.72

BSSC Standards

GSP-11KMS-04KMS-05KMS-06KMS-09NOS-05NOS-08TIS-07

SEC Custody (Digital Assets)

SEC-CD-02SEC-CD-03SEC-CD-04SEC-CD-05SEC-CD-16

India DPDPA

Act.8(5)Rules.6(1)(b)Rules.Sch1.B.7

ISO 17799 (legacy)

11.2.2

COBIT 4.1 (legacy)

PO4.11