ACC-04Identity and Access
Privileged access controlled
Administrative access is limited, separately approved, monitored and time-bound where possible.
Why it exists
Standing administrative access is the largest single blast radius.
What usually proves it
Privileged account inventory, approval records, session logs.
Smaller organizations
Two named admins, reviewed monthly.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC6.1
- Fully addressedISO/IEC 27001 Annex A · A.8.2
- Fully addressedNIST Cybersecurity Framework · PR.AA-05
- Fully addressedPCI DSS · 7.2.2
- Partially addressedHIPAA Security Rule · 164.308(a)(4) — Through access authorisation.
- Deliberately absentGDPR — No privileged access concept; covered generally by Art. 32.
- Deliberately absentEU AI Act — Not addressed.
- Deliberately absentNIST AI Risk Management Framework — Not addressed at control level.