ACC-04Identity and Access

Privileged access controlled

Administrative access is limited, separately approved, monitored and time-bound where possible.

Why it exists

Standing administrative access is the largest single blast radius.

What usually proves it

Privileged account inventory, approval records, session logs.

Smaller organizations

Two named admins, reviewed monthly.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC6.1
  • Fully addressedISO/IEC 27001 Annex A · A.8.2
  • Fully addressedNIST Cybersecurity Framework · PR.AA-05
  • Fully addressedPCI DSS · 7.2.2
  • Partially addressedHIPAA Security Rule · 164.308(a)(4) — Through access authorisation.
  • Deliberately absentGDPR — No privileged access concept; covered generally by Art. 32.
  • Deliberately absentEU AI Act — Not addressed.
  • Deliberately absentNIST AI Risk Management Framework — Not addressed at control level.