Description
Applicability
-
The information resource owner, or designee, is responsible for ensuring that the measures described in this Control are implemented. The intended audience for this Control includes, but is not limited to, all information resources owners and custodians.
Implementation
-
1
Accounts shall be created with least privilege for routine tasks.
-
2
Privileges shall be escalated only as needed, and consider separation of duties (see Security Control AC-5).