IAC-21—Least Privilege
Weight: 10
>Control Description
Mechanisms exist to utilize the concept of least privilege, allowing only authorized access to processes necessary to accomplish assigned tasks in accordance with organizational business functions.
>Cross-Framework Mappings
PCI DSS v4.0.1
CMMC v2.0
Canada ITSP 10.171
Australia ISM
EU CRA Annexes
EU DORA
Spain ENS
SOC 2 TSC (Detailed)
NIST SP 800-171 Rev 3
NIST SP 800-171A Rev 3
NIST SP 800-207 Zero Trust
DHS TIC 3.0
GLBA (16 CFR 314)
HIPAA Simplification 2013
NY DFS 23 NYCRR 500
Ask AI
Configure your API key to use AI features.