Under active development Content is continuously updated and improved

AC-06(10)Least Privilege | Prohibit Non-privileged Users from Executing Privileged Functions

Moderate
Core Control

>Control Description

Prevent non-privileged users from executing privileged functions.

>Discussion

Privileged functions include disabling, circumventing, or altering implemented security or privacy controls, establishing system accounts, performing system integrity checks, and administering cryptographic key management activities. Non-privileged users are individuals who do not possess appropriate authorizations. Privileged functions that require protection from non-privileged users include circumventing intrusion detection and prevention mechanisms or malicious code protection mechanisms.

Preventing non-privileged users from executing privileged functions is enforced by AC-3.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.