The use of privileged credentials is limited to processes for which they are required
Privileged accounts represent higher risk to IT and OT assets. An organization may control the use of privileged credentials through administrative means, such as a policy that restricts the use of a local administrative accounts to required tasks and prohibits use of privileged accounts for day-to-day work functions. Alternatively, an organization may implement technical controls to restrict privileged accounts from accessing resources that do not require elevated privileges.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ACCESS-1b, ACCESS-1d, ACCESS-1g, ACCESS-1h, ACCESS-1i.