Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AC-06: Least Privilege #616

Closed
3 tasks done
kniz-raft opened this issue Jan 29, 2021 · 2 comments
Closed
3 tasks done

AC-06: Least Privilege #616

kniz-raft opened this issue Jan 29, 2021 · 2 comments
Assignees
Labels

Comments

@kniz-raft
Copy link

kniz-raft commented Jan 29, 2021

AC:

  • Control implementation statement has been reviewed by Raft for technical accuracy
  • Control implementation statement has passed QASP review

DoD:

  • Control implementation statement has been documented in GitHub

Control Description:
The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.

AC-6 (2) Additional FedRAMP Requirements and Guidance: Examples of security functions include but are not limited to: establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters, system programming, system and security administration, other privileged functions.

@rnafarrete
Copy link

Created pull request for AC-06

@rnafarrete
Copy link

Updated based on comments.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants