Third party vendors or services have privileged access that is not logged
Context and Guidance: Privileged access, such as an administrator account, represents a higher level of risk to the function, given the potential for an administrator to make broad and irreversible changes to assets (such as networks, systems, and applications).
If you provision third parties with privileged access, you should ensure that logging data is collected, and that the access does not circumvent your security controls.