AC-6(3): Network Access to Privileged Commands

Control Family:

Access Control

Parent Control:

AC-6: Least Privilege

CSF v1.1 References:

CSF v2.0 References:

PF v1.0 References:

Threats Addressed:

Baselines:

  • High
  • OT High (SP 800-82r3)

Previous Version:

Control Statement

Authorize network access to [Assignment: organization-defined privileged commands] only for [Assignment: organization-defined compelling operational needs] and document the rationale for such access in the security plan for the system.

Supplemental Guidance

Network access is any access across a network connection in lieu of local access (i.e., user being physically present at the device).

OT Discussion

When OT components (e.g., PLCs) cannot support the logging of privileged functions, other system components within the authorization boundary may be used (e.g., engineering workstations or physical access monitoring).