NIST800-AC-6 AC-6 Least Privilege
NIST800-AC-6 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
AC-6 Least Privilege. Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) (closest match)
- SOC2-CC6.1 CC6.1 Logical access security over protected information assets (closest match)
- SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties (closest match)
- SOC2-P5.1 P5.1 Data subject access (closest match)
- SOC2-PI1.3 PI1.3 Controls over system processing (closest match)
HIPAA Security Rule
- 164.308(a)(3)(i) Workforce Security (Standard) (closest match)
- 164.308(a)(4)(i) Information Access Management (Standard) (closest match)
- 164.308(a)(4)(ii)(B) Access Authorization (Addressable) (closest match)
- 164.312(a)(1) Access Control (Standard) (closest match)
- 164.312(a)(2)(ii) Emergency Access Procedure (Required) (closest match)
- 164.314(b)(1) Requirements for Group Health Plans (Standard) (closest match)
- 164.314(b)(2) Implementation Specifications for Group Health Plans (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: AC - Access Control), in our words, not a statement of the standard and not binding on an assessor.
- the access-control policy and procedures
- the account-management and privilege records
- the periodic access-review output