AC-6 Least Privilege
Description
Organizations employ least privilege for specific duties and information systems. The principle of least privilege is also applied to information system processes, ensuring that the processes operate at privilege levels no higher than necessary to accomplish required organizational missions/business functions.
Organizations consider the creation of additional processes, roles, and information system accounts as necessary, to achieve least privilege.
Organizations also apply least privilege to the development, implementation, and operation of organizational information systems.
Applicability
The information resource owner, or designee, is responsible for ensuring that the measures described in this Control are implemented.
The intended audience for this Control includes, but is not limited to, all information resources owners and custodians.
Implementation
TAMU-CC shall employ least privilege for routine tasks, and that privileges shall be escalated only as required for a specific action, as follows:
- Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.
- Ensures users with privileged (also known as administrative or special access) accounts are aware of the extraordinary responsibilities associated with the use of privileged accounts.
Revision History
Last Updated: February 21, 2025
Previous Versions:
- June 29, 2023
- May 31, 2022
- March 25, 2021
- September 16, 2019