AC-6(8)—Least Privilege
Secret
Technical
>Control Description
LEAST PRIVILEGE | PRIVILEGE LEVELS FOR CODE EXECUTION The information system prevents ⚙organization-defined software from executing at higher privilege levels than users executing the software.
>Supplemental Guidance
In certain situations, software applications/programs need to execute with elevated privileges to perform required functions. However, if the privileges required for execution are at a higher level than the privileges assigned to organizational users invoking such applications/programs, those users are indirectly provided with greater privileges than assigned by organizations.
Ask AI
Configure your API key to use AI features.