graphgrc

SCF - IAC-21 - Least Privilege

Mechanisms exist to utilize the concept of least privilege, allowing only authorized access to processes necessary to accomplish assigned tasks in accordance with organizational business functions.

Mapped framework controls

ISO 27002

NIST 800-53

SOC 2

Control questions

Does the organization utilize the concept of least privilege, allowing only authorized access to processes necessary to accomplish assigned tasks in accordance with organizational business functions?