A complete and current register of identities (users) with privileged access is not maintained
Context and Guidance: Privileged access, such as an administrator account, represents a higher level of risk to the function, given the potential for an administrator to make broad and irreversible changes to assets (such as networks, systems, and applications).
To support privileged access management activities, you should:
- Ensure that identities (users) provisioned privilege access are recorded within a privileged access register maintained separately from the master access control lists retained on individual assets;
- Automate and optimise the steps taken to ensure that the register of identities (users) with privileged access is maintained; and
- Establish a periodicity within which privileged access reviews are to be completed with reference the register.