The use of privileged credentials is limited to processes for which they are required
Context and Guidance: Privileged accounts represent higher risk to IT and OT assets. An organisation may control the use of privileged credentials through administrative means, such as a policy that restricts the use of a local administrative accounts to required tasks and prohibits use of privileged accounts for day-to-day work functions. Alternatively, an organisation may implement technical controls to restrict privileged accounts from accessing resources that do not require elevated privileges.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ACCESS-1b, ACCESS-1d, ACCESS-1g, ACCESS-1h, ACCESS-1i.