πΌ AC-6 LEAST PRIVILEGE
- Contextual name: πΌ AC-6 LEAST PRIVILEGE
- ID:
/frameworks/nist-sp-800-53-r4/ac/06
- Located in: πΌ AC ACCESS CONTROL
Descriptionβ
The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.
Similarβ
- Internal
- ID:
dec-c-60a60b03
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST CSF v1.1 β πΌ PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties | 17 | 52 | ||
πΌ NIST CSF v1.1 β πΌ PR.DS-5: Protections against data leaks are implemented | 47 | 66 |
Sub Sectionsβ
Policies (3)β
Policy | Logic Count | Flags |
---|---|---|
π AWS IAM User has inline or directly attached policies π’ | 1 | π x1, π’ x5 |
π Google GCE Instance is configured to use the Default Service Account with full access to all Cloud APIs π’ | 1 | π’ x6 |
π Google IAM Users are assigned the Service Account User or Service Account Token Creator roles at Project level π’ | 1 | π’ x6 |
Internal Rulesβ
Rule | Policies | Flags |
---|---|---|
βοΈ dec-x-4157c58a | 1 |