Cyber Insurance Subjectivity Tracker

Controls / Administrator accounts

Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: check and sign off every request for admin rights when it is made, and keep a list of admin accounts.

In Australia

Maturity Level One

ClauseThe held text, and the evidence an assessor asks for
ISM-1507
Essential Eight, Maturity Level One

Requests for privileged access to systems, applications and data repositories are validated when first requested. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1507 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Privileged access request forms or tickets with validation and approver; Sample of new privileged accounts traced to approved requests

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 7.2.2
PCI DSS v4.0.1 (add-on)
User access assigned by job function and least privilege

Access for every user, including privileged users, must be assigned on the basis of the user's job classification and function, and restricted to the least privileges needed to perform that person's responsibilities. The guidance explains that once role needs are defined under 7.2.1, individuals can be granted access by placing them in the matching roles, gives the example that a database or backup administrator should not hold the full privileges of a systems administrator, and suggests entities may consider privileged access management that grants elevated rights only when needed and removes them afterwards. Objective under the customized approach: access to systems and data is confined to what each job function needs, as set out in the related access roles.

evidence an assessor asks for User access provisioning procedure referencing job classification and least privilege; Export of user-to-role and user-to-group assignments, including privileged groups; Sample of privileged user records compared with their job descriptions; PAM tool configuration or just-in-time elevation logs where used

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 5.1
CIS Controls v8.1
Establish and Maintain an Inventory of Accounts

Keep a register of every account the enterprise manages, covering both user and administrator accounts. At a minimum each entry should hold the person's name, the username, the start and end dates, and the department. Confirm that every active account is authorised on a regular cycle of at least once a quarter.

The requirement's own words: at least once a quarter

evidence an assessor asks for Account inventory showing name, username, start and end dates and department for user and admin accounts; Quarterly account validation records; Identity management standard naming who authorises accounts and the quarterly validation cadence; Reconciliation of the account inventory against the HR system showing mismatches and actions taken; Inventory entries for service and shared accounts with an accountable owner recorded

PR.AA-05
NIST CSF 2.0

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

evidence an assessor asks for Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records

FTC Safeguards Rule, when it applies

Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.

ClauseThe held text, and the evidence an assessor asks for
314.4(c)(1)
FTC Safeguards Rule (add-on)
314.4(c)(1) Access controls

Access controls, technical and where appropriate physical, are implemented and periodically reviewed to authenticate and permit access only to authorised users so as to protect against unauthorised acquisition of customer information, and to limit authorised users to the customer information they need for their duties and functions, or, for customers, to their own information.

evidence an assessor asks for Access control policy and user access reviews; Role-based permissions limiting access to need; Customer self-service access limited to own records

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 7.2.2
PCI DSS v4.0.1 (add-on)
User access assigned by job function and least privilege

Access for every user, including privileged users, must be assigned on the basis of the user's job classification and function, and restricted to the least privileges needed to perform that person's responsibilities. The guidance explains that once role needs are defined under 7.2.1, individuals can be granted access by placing them in the matching roles, gives the example that a database or backup administrator should not hold the full privileges of a systems administrator, and suggests entities may consider privileged access management that grants elevated rights only when needed and removes them afterwards. Objective under the customized approach: access to systems and data is confined to what each job function needs, as set out in the related access roles.

evidence an assessor asks for User access provisioning procedure referencing job classification and least privilege; Export of user-to-role and user-to-group assignments, including privileged groups; Sample of privileged user records compared with their job descriptions; PAM tool configuration or just-in-time elevation logs where used

In United Kingdom

ClauseThe held text, and the evidence an assessor asks for
CE-AC.4
Cyber Essentials
Privileged Account Approval and Tracking

Implement an approval process and keep track of privileged (administrative) accounts. The granting of privileges must be controlled.

evidence an assessor asks for list of all admin accounts with owner; approval records; PAM tool inventory

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 7.2.2
PCI DSS v4.0.1 (add-on)
User access assigned by job function and least privilege

Access for every user, including privileged users, must be assigned on the basis of the user's job classification and function, and restricted to the least privileges needed to perform that person's responsibilities. The guidance explains that once role needs are defined under 7.2.1, individuals can be granted access by placing them in the matching roles, gives the example that a database or backup administrator should not hold the full privileges of a systems administrator, and suggests entities may consider privileged access management that grants elevated rights only when needed and removes them afterwards. Objective under the customized approach: access to systems and data is confined to what each job function needs, as set out in the related access roles.

evidence an assessor asks for User access provisioning procedure referencing job classification and least privilege; Export of user-to-role and user-to-group assignments, including privileged groups; Sample of privileged user records compared with their job descriptions; PAM tool configuration or just-in-time elevation logs where used

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.2
ISO/IEC 27001:2022 (lens)
Privileged access rights

The granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2.

evidence an assessor asks for Statement of Applicability entry for control A.8.2, showing inclusion or justified exclusion, implementation status and the risks it treats; An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry; Privileged access management configuration showing time-limited elevation, step-up authentication and session recording; Privileged access review records performed periodically and after organizational changes

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule