πΌ AC-6 Least Privilege (M)(H)
- Contextual name: πΌ AC-6 Least Privilege (M)(H)
- ID:
/frameworks/fedramp-high-security-controls/ac/06
- Located in: πΌ Access Control
Descriptionβ
Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.
Similarβ
- Sections
/frameworks/nist-sp-800-53-r5/ac/06
- Internal
- ID:
dec-c-e3bc71a5
- ID:
Similar Sections (Take Policies From)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST SP 800-53 Revision 5 β πΌ AC-6 Least Privilege | 10 | 21 | 26 |
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ FedRAMP Moderate Security Controls β πΌ AC-6 Least Privilege (M)(H) | 6 | 33 |
Sub Sectionsβ
Policies (7)β
Policy | Logic Count | Flags |
---|---|---|
π AWS Account Root User has active access keys π’ | 1 | π’ x6 |
π AWS EC2 Instance IMDSv2 is not enabled π’ | 1 | π’ x6 |
π AWS IAM Policy allows full administrative privileges π’ | 1 | π’ x6 |
π AWS IAM User has inline or directly attached policies π’ | 1 | π x1, π’ x5 |
π AWS IAM User with credentials unused for 45 days or more is not disabled π’ | 1 | π’ x6 |
π AWS RDS Snapshot is publicly accessible π’ | 1 | π’ x6 |
π AWS S3 Bucket is not configured to block public access π’ | 1 | π’ x6 |