HomeControl Library › 3.1.7
3.1 Access Control1 ptPOA&M-eligible

3.1.7 — Restrict and log privileged functions

Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.

Ordinary users can't run admin functions — and when admin functions run, you log it.

What it actually means

Non-privileged users must be prevented from executing privileged functions, and the execution of privileged functions must be captured in audit logs. In practice: enforce least privilege so standard users can't run admin tools, and make sure your logging captures privileged and administrative actions.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library