PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Threats Addressed:
Subcategory is new to this version of the framework and incorporates the following items from the previous version: PR.AC-1: Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes, PR.AC-3: Remote access is managed, PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
1st: 1st Party Risk
Ex1: Review logical and physical access privileges periodically and whenever someone changes roles or leaves the organization, and promptly rescind privileges that are no longer needed
Ex2: Take attributes of the requester and the requested resource into account for authorization decisions (e.g., geolocation, day/time, requester endpoint's cyber health)
Ex3: Restrict access and privileges to the minimum necessary (e.g., zero trust architecture)
Ex4: Periodically review the privileges associated with critical business functions to confirm proper separation of duties
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
AC-1: Policy and Procedures
Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] access control policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the implementation…
AC-2: Account Management
Define and document the types of accounts allowed and specifically prohibited for use within the system; Assign account managers; Require [Assignment: organization-defined prerequisites and criteria] for group and role membership; Specify: Authorized users of the system; Group and role membership; and Access authorizations (i.e., privileges) and [Assignment: organization-defined attributes (as required)] for each account; Require…
AC-3: Access Enforcement
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
AC-5: Separation of Duties
Identify and document [Assignment: organization-defined duties of individuals] ; and Define system access authorizations to support separation of duties.
AC-6: Least Privilege
Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.
AC-10: Concurrent Session Control
Limit the number of concurrent sessions for each [Assignment: organization-defined account and/or account types] to [Assignment: organization-defined number].
AC-16: Security and Privacy Attributes
Provide the means to associate [Assignment: organization-defined types of security and privacy attributes] with [Assignment: organization-defined security and privacy attribute values] for information in storage, in process, and/or in transmission; Ensure that the attribute associations are made and retained with the information; Establish the following permitted security and privacy attributes from the attributes defined in…
AC-17: Remote Access
Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and Authorize each type of remote access to the system prior to allowing such connections.
AC-18: Wireless Access
Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access; and Authorize each type of wireless access to the system prior to allowing such connections.
AC-19: Access Control for Mobile Devices
Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and Authorize the connection of mobile devices to organizational systems.
AC-24: Access Control Decisions
[Assignment (one or more): establish procedures, implement mechanisms] to ensure [Assignment: organization-defined access control decisions] are applied to each access request prior to access enforcement.
IA-13: Identity Providers and Authorization Servers
Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and access rights supporting authentication and authorization decisions in accordance with [Assignment: organization-defined policy] using [Assignment: organization-defined mechanisms].
NIST SP 800-171 Revision 3.0
03.01.01: Account Management
Define the types of system accounts allowed and prohibited. Create, enable, modify, disable, and remove system accounts in accordance with policy, procedures, prerequisites, and criteria. Specify: Authorized users of the system, Group and role membership, and Access authorizations (i.e., privileges) for each account. Authorize access to the system based on: A valid access authorization and…
03.01.02: Access Enforcement
Enforce approved authorizations for logical access to CUI and system resources in accordance with applicable access control policies.
03.01.04: Separation of Duties
Identify the duties of individuals requiring separation. Define system access authorizations to support separation of duties.
03.01.05: Least Privilege
Allow only authorized system access for users (or processes acting on behalf of users) that is necessary to accomplish assigned organizational tasks. Authorize access to [Assignment: organization-defined security functions] and [Assignment: organization-defined security-relevant information]. Review the privileges assigned to roles or classes of users [Assignment: organization-defined frequency] to validate the need for such privileges. Reassign…
03.01.06: Least Privilege — Privileged Accounts
Restrict privileged accounts on the system to [Assignment: organization-defined personnel or roles].. Require that users (or roles) with privileged accounts use non-privileged accounts when accessing non-security functions or non-security information.
03.01.07: Least Privilege — Privileged Functions
Prevent non-privileged users from executing privileged functions. Log the execution of privileged functions.
03.01.12: Remote Access
Establish usage restrictions, configuration requirements, and connection requirements for each type of allowable remote system access. Authorize each type of remote system access prior to establishing such connections. Route remote access to the system through authorized and managed access control points. Authorize the remote execution of privileged commands and remote access to security-relevant information.
03.01.16: Wireless Access
Establish usage restrictions, configuration requirements, and connection requirements for each type of wireless access to the system. Authorize each type of wireless access to the system prior to establishing such connections. Disable, when not intended for use, wireless networking capabilities prior to issuance and deployment. Protect wireless access to the system using authentication and encryption.
03.01.18: Access Control for Mobile Devices
Establish usage restrictions, configuration requirements, and connection requirements for mobile devices. Authorize the connection of mobile devices to the system. Implement full-device or container-based encryption to protect the confidentiality of CUI on mobile devices.
03.13.08: Transmission and Storage Confidentiality
Implement cryptographic mechanisms to prevent the unauthorized disclosure of CUI during transmission and while in storage.
03.15.01: Policy and Procedures
Develop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for the protection of CUI. Review and update policies and procedures [Assignment: organization-defined frequency].
Cloud Controls Matrix v4.0
CCC-04: Unauthorized Change Protection
Restrict the unauthorized addition, removal, update, and management of organization assets.
CEK-10: Key Generation
Generate Cryptographic keys using industry accepted cryptographic libraries specifying the algorithm strength and the random number generator used.
CEK-11: Key Purpose
Manage cryptographic secret and private keys that are provisioned for a unique purpose.
CEK-12: Key Rotation
Rotate cryptographic keys in accordance with the calculated cryptoperiod, which includes provisions for considering the risk of information disclosure and legal and regulatory requirements.
CEK-13: Key Revocation
Define, implement and evaluate processes, procedures and technical measures to revoke and remove cryptographic keys prior to the end of its established cryptoperiod, when a key is compromised, or an entity is no longer part of the organization, which include provisions for legal and regulatory requirements.
CEK-14: Key Destruction
Define, implement and evaluate processes, procedures and technical measures to destroy keys stored outside a secure environment and revoke keys stored in Hardware Security Modules (HSMs) when they are no longer needed, which include provisions for legal and regulatory requirements.
CEK-15: Key Activation
Define, implement and evaluate processes, procedures and technical measures to create keys in a pre-activated state when they have been generated but not authorized for use, which include provisions for legal and regulatory requirements.
CEK-16: Key Suspension
Define, implement and evaluate processes, procedures and technical measures to monitor, review and approve key transitions from any state to/from suspension, which include provisions for legal and regulatory requirements.
CEK-17: Key Deactivation
Define, implement and evaluate processes, procedures and technical measures to deactivate keys at the time of their expiration date, which include provisions for legal and regulatory requirements.
CEK-18: Key Archival
Define, implement and evaluate processes, procedures and technical measures to manage archived keys in a secure repository requiring least privilege access, which include provisions for legal and regulatory requirements.
CEK-19: Key Compromise
Define, implement and evaluate processes, procedures and technical measures to use compromised keys to encrypt information only in controlled circumstance, and thereafter exclusively for decrypting data and never for encrypting data, which include provisions for legal and regulatory requirements.
CEK-20: Key Recovery
Define, implement and evaluate processes, procedures and technical measures to assess the risk to operational continuity versus the risk of the keying material and the information it protects being exposed if control of the keying material is lost, which include provisions for legal and regulatory requirements.
CEK-21: Key Inventory Management
Define, implement and evaluate processes, procedures and technical measures in order for the key management system to track and report all cryptographic materials and changes in status, which include provisions for legal and regulatory requirements.
IAM-01: Identity and Access Management Policy and Procedures
Establish, document, approve, communicate, implement, apply, evaluate and maintain policies and procedures for identity and access management. Review and update the policies and procedures at least annually.
IAM-03: Identity Inventory
Manage, store, and review the information of system identities, and level of access.
IAM-04: Separation of Duties
Employ the separation of duties principle when implementing information system access.
IAM-05: Least Privilege
Employ the least privilege principle when implementing information system access.
IAM-06: User Access Provisioning
Define and implement a user access provisioning process which authorizes, records, and communicates access changes to data and assets.
IAM-07: User Access Changes and Revocation
De-provision or respectively modify access of movers / leavers or system identity changes in a timely manner in order to effectively adopt and communicate identity and access management policies.
IAM-08: User Access Review
Review and revalidate user access for least privilege and separation of duties with a frequency that is commensurate with organizational risk tolerance.
IAM-09: Segregation of Privileged Access Roles
Define, implement and evaluate processes, procedures and technical measures for the segregation of privileged access roles such that administrative access to data, encryption and key management capabilities and logging capabilities are distinct and separated.
IAM-10: Management of Privileged Access Roles
Define and implement an access process to ensure privileged access roles and rights are granted for a time limited period, and implement procedures to prevent the culmination of segregated privileged access.
IAM-11: CSCs Approval for Agreed Privileged Access Roles
Define, implement and evaluate processes and procedures for customers to participate, where applicable, in the granting of access for agreed, high risk (as defined by the organizational risk assessment) privileged access roles.
IAM-12: Safeguard Logs Integrity
Define, implement and evaluate processes, procedures and technical measures to ensure the logging infrastructure is read-only for all with write access, including privileged access roles, and that the ability to disable it is controlled through a procedure that ensures the segregation of duties and break glass procedures.
IAM-16: Authorization Mechanisms
Define, implement and evaluate processes, procedures and technical measures to verify access to data and system functions is authorized.
IVS-03: Network Security
Monitor, encrypt and restrict communications between environments to only authenticated and authorized connections, as justified by the business. Review these configurations at least annually, and support them by a documented justification of all allowed services, protocols, ports, and compensating controls.
IVS-06: Segmentation and Segregation
Design, develop, deploy and configure applications and infrastructures such that CSP and CSC (tenant) user access and intra-tenant access is appropriately segmented and segregated, monitored and restricted from other tenants.
LOG-02: Audit Logs Protection
Define, implement and evaluate processes, procedures and technical measures to ensure the security and retention of audit logs.
LOG-04: Audit Logs Access and Accountability
Restrict audit logs access to authorized personnel and maintain records that provide unique access accountability.
LOG-09: Log Protection
The information system protects audit records from unauthorized access, modification, and deletion.
UEM-05: Endpoint Management
Define, implement and evaluate processes, procedures and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data.
UEM-14: Third-Party Endpoint Security Posture
Define, implement and evaluate processes, procedures and technical and/or contractual measures to maintain proper security of third-party endpoints with access to organizational assets.
Critical Security Controls Version 8.1
3.3: Configure Data Access Control Lists
Configure data access control lists based on a user's need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications.
6.8: Define and Maintain Role-Based Access Control
Define and maintain role-based access control, through determining and documenting the access rights necessary for each role within the enterprise to successfully carry out its assigned duties. Perform access control reviews of enterprise assets to validate that all privileges are authorized, on a recurring schedule at a minimum annually, or more frequently.