Privileged access rights
Purpose
Limit and oversee privileged access so only authorised users, components and services hold elevated rights.
How to meet this control
In short: Restrict and manage allocation and use of privileged access.
- Step 01Inventory every privileged role across cloud tenants, servers, databases and SaaS admin consoles, and reduce standing admin membership to the minimum
- Step 02Implement just-in-time elevation through tooling such as Entra Privileged Identity Management, AWS IAM Identity Center or a PAM product, so admin rights are granted for a time-boxed window with approval
- Step 03Give each administrator a separate named admin account distinct from their day-to-day account used for email and browsing
- Step 04Vault shared service and break-glass credentials in a privileged access manager (CyberArk, Delinea, HashiCorp Vault) with checkout logging
- Step 05Force phishing-resistant MFA and step-up re-authentication on every privileged session
- Step 06Run a quarterly privileged access review and remove rights tied to leavers or role changes
Tip: Just-in-time/approved admin access and a record of who holds it.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Grant privileged rights through a formal authorisation process tied to the access control policy
- ›Identify who genuinely needs privileged access per system and allocate it on a least-privilege basis
- ›Keep a record of all privileges allocated and set expiry rules for them
- ›Require stronger authentication for privileged sessions, such as re-authentication or step-up
- ›Review privileged users regularly and after organisational changes
- ›Avoid shared generic admin IDs and use temporary just-in-time access where possible
- ›Log all privileged access for audit, and give each admin a unique identity
- ›Use privileged identities only for admin tasks, with a separate normal account for email and browsing
Audit evidence to keep
- - Register of privileged accounts mapped to named individuals and systems
- - Just-in-time elevation logs showing time-boxed grants with approver and reason
- - Screenshot of MFA enforcement on privileged or admin roles
- - Quarterly privileged access review record with sign-off
- - Break-glass account checkout log from the password vault
Common mistakes
- - Approving access in chat with no retained record
- - Copying access from another user without checking least privilege
- - Reviewing access but not proving removals were completed
Owner, cadence, and proof
Assign one accountable owner for A.8.2. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.