πΌ PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties
- Contextual name: πΌ PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties
- ID:
/frameworks/nist-csf-v1.1/pr-ac/04
- Located in: πΌ Identity Management, Authentication and Access Control (PR.AC)
Descriptionβ
Empty...
Similarβ
- Sections
/frameworks/iso-iec-27001-2013/06/01/02
/frameworks/iso-iec-27001-2013/09/01/02
/frameworks/iso-iec-27001-2013/09/02/03
/frameworks/iso-iec-27001-2013/09/04/01
/frameworks/iso-iec-27001-2013/09/04/04
/frameworks/iso-iec-27001-2013/09/04/05
/frameworks/nist-sp-800-53-r4/ac/01
/frameworks/nist-sp-800-53-r4/ac/02
/frameworks/nist-sp-800-53-r4/ac/03
/frameworks/nist-sp-800-53-r4/ac/05
/frameworks/nist-sp-800-53-r4/ac/06
/frameworks/nist-sp-800-53-r4/ac/14
/frameworks/nist-sp-800-53-r4/ac/16
/frameworks/nist-sp-800-53-r4/ac/24
- Internal
- ID:
dec-c-2c2dde09
- ID:
Similar Sections (Take Policies From)β
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST CSF v2.0 β πΌ PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties | 57 |
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (34)β
Policy | Logic Count | Flags |
---|---|---|
π AWS Account IAM Access Analyzer is not enabled for all regions π’ | 1 | π’ x6 |
π AWS Account Root User credentials were used is the last 30 days π΄π’ | 1 | π΄ x1, π’ x6 |
π AWS Account Root User has active access keys π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted CIFS traffic π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted DNS traffic π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted FTP traffic π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted ICMP traffic π’ | 1 |