Give everyone the minimum access they need — and tightly control privileged accounts.
What it actually means
Least privilege applied to the people who can do the most damage. Privileged (admin) functions should be restricted to dedicated administrative accounts that are separate from daily-use accounts, granted only to those who need them, and reviewed regularly. Just-in-time elevation is the gold standard but not required.
Pass or fail — an assessor needs a "yes" to each
- Privileged functions are limited to named/dedicated admin accounts.
- Admins use separate accounts for privileged work vs. daily use.
- Privileged access is reviewed periodically and removed when no longer needed.
What to have ready
- List of privileged accounts and who holds them
- Policy requiring separate admin accounts
- Evidence of periodic privileged-access review (and ideally JIT/PIM logs)
Where teams trip up
- Day-to-day accounts that also carry admin rights
- Shared admin credentials
- Standing privileged access nobody reviews
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
3.1.6 — Use non-privileged accounts for nonsecurity work3.1.7 — Block + log privileged functions for non-privileged users
More in Access Control (3.1)
3.1.1 — Limit who (and what) can get in3.1.2 — Limit what users can do3.1.3 — Control the flow of CUI3.1.4 — Separate duties3.1.6 — Use non-privileged accounts for routine work3.1.7 — Restrict and log privileged functions3.1.8 — Limit failed logons3.1.9 — Show privacy and security notices3.1.10 — Lock idle screens3.1.11 — End sessions automatically3.1.12 — Monitor and control remote access3.1.13 — Encrypt remote access sessions3.1.14 — Funnel remote access through managed points3.1.15 — Authorize privileged remote actions3.1.16 — Authorize wireless access first3.1.17 — Protect wireless with authentication + encryption3.1.18 — Control mobile device connections3.1.19 — Encrypt CUI on mobile devices3.1.20 — Control connections to external systems3.1.21 — Limit portable storage on external systems3.1.22 — Control what goes on public systems