AC-6(1): Authorize Access to Security Functions

Control Family:

Access Control

Parent Control:

AC-6: Least Privilege

CSF v1.1 References:

CSF v2.0 References:

PF v1.0 References:

Threats Addressed:

Baselines:

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Previous Version:

Control Statement

Authorize access for [Assignment: organization-defined individuals and roles] to:

  1. [Assignment: organization-defined security functions (deployed in hardware, software, and firmware)] ; and
  2. [Assignment: organization-defined security-relevant information].

Supplemental Guidance

Security functions include establishing system accounts, configuring access authorizations (i.e., permissions, privileges), configuring settings for events to be audited, and establishing intrusion detection parameters. Security-relevant information includes filtering rules for routers or firewalls, configuration parameters for security services, cryptographic key management information, and access control lists. Authorized personnel include security administrators, system administrators, system security officers, system programmers, and other privileged users.

OT Discussion

When OT components (e.g., PLCs) cannot support the logging of privileged functions, other system components within the authorization boundary may be used (e.g., engineering workstations or physical access monitoring).