💼 AC-6(2) Non-privileged Access for Nonsecurity Functions (M)(H)
- Contextual name: 💼 AC-6(2) Non-privileged Access for Nonsecurity Functions (M)(H)
- ID:
/frameworks/fedramp-high-security-controls/ac/06/02
- Located in: 💼 AC-6 Least Privilege (M)(H)
Description
Require that users of system accounts (or roles) with access to [FedRAMP Assignment: all security functions] use non-privileged accounts or roles, when accessing nonsecurity functions.
AC-6 (2) Additional FedRAMP Requirements and Guidance:
Guidance: Examples of security functions include but are not limited to: establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters, system programming, system and security administration, other privileged functions.
Similar
- Sections
/frameworks/nist-sp-800-53-r5/ac/06/02
- Internal
Similar Sections (Take Policies From)
Similar Sections (Give Policies To)
Sub Sections
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (4)
Internal Rules
Rule | Policies | Flags |
---|
✉️ dec-x-157aa4b9 | 1 | |