3.1 Access Control3 pts

3.1.5 — Least privilege (especially for admins)

Employ the principle of least privilege, including for specific security functions and privileged accounts.

Give everyone the minimum access they need — and tightly control privileged accounts.

What it actually means

Least privilege applied to the people who can do the most damage. Privileged (admin) functions should be restricted to dedicated administrative accounts that are separate from daily-use accounts, granted only to those who need them, and reviewed regularly. Just-in-time elevation is the gold standard but not required.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Access Control (3.1)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.