1. Home
  2. Frameworks and Standards
  3. NIST SP 800-53
  4. NIST SP 800-53 – AC-2(7) – Account Management | Privileged User Accounts

NIST SP 800-53 – AC-2(7) – Account Management | Privileged User Accounts

Control(s)

(a) Establish and administer privileged user accounts in accordance with [Selection: a role-based access scheme; an attribute-based access scheme];
(b) Monitor privileged role or attribute assignments;
(c) Monitor changes to roles or attributes; and
(d) Revoke access when privileged role or attribute assignments are no longer appropriate.

Additional Details (Discussion)

Privileged roles are organization-defined roles assigned to individuals that allow those individuals to perform certain security-relevant functions that ordinary users are not authorized to perform. Privileged roles include key management, account management, database administration, system and network administration, and web administration. A role-based access scheme organizes permitted system access and privileges into roles. In contrast, an attribute-based access scheme specifies allowed system access and privileges based on attributes.

Related Control(s)

  • None.

Reference(s)

Updated on July 16, 2022
Was this article helpful?

Related Articles