Cyber Insurance Subjectivity Tracker

Controls / Administrator accounts

Administrators use a separate privileged account and environment for admin work only, with no internet or email on it

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: give administrators a separate admin account used only for admin work, with no web browsing or email on it.

In Australia

Maturity Level One

ClauseThe held text, and the evidence an assessor asks for
ISM-0445
Essential Eight, Maturity Level One

Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-0445 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for List of privileged users with their separate privileged accounts; Account naming standard and directory export

ISM-1175
Essential Eight, Maturity Level One

Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1175 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Proxy, firewall or policy configuration blocking internet, email and web access for privileged accounts; List of privileged accounts explicitly authorised for online services

ISM-1380
Essential Eight, Maturity Level One

Privileged users use separate privileged and unprivileged operating environments. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1380 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Architecture showing separate privileged and unprivileged operating environments; Evidence of dedicated administration workstations or virtual environments

ISM-1688
Essential Eight, Maturity Level One

Unprivileged user accounts cannot logon to privileged operating environments. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1688 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Group policy or equivalent denying unprivileged accounts logon to privileged environments; Test results of an attempted unprivileged logon

ISM-1689
Essential Eight, Maturity Level One

Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1689 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Group policy or equivalent denying privileged accounts logon to unprivileged workstations and servers; Logon event review showing no privileged logons to standard hosts

ISM-1883
Essential Eight, Maturity Level One

Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1883 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Approval records and scope for each privileged account authorised to access online services; Configuration limiting those accounts to the approved services

Maturity Level Two

Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.

ClauseThe held text, and the evidence an assessor asks for
ISM-1387
Essential Eight, Maturity Level Two

Administrative activities are conducted through jump servers. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1387 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Network rules forcing administration traffic through jump servers; Jump server access logs

ISM-1687
Essential Eight, Maturity Level Two

Privileged operating environments are not virtualised within unprivileged operating environments. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1687 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Virtualisation architecture showing privileged environments are not hosted inside unprivileged ones; Configuration review of administration virtual machines

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 5.4
CIS Controls v8.1
Restrict Administrator Privileges to Dedicated Administrator Accounts

Confine administrator privileges on enterprise assets to accounts used only for administration. Everyday computing, for example web browsing, email and office productivity tools, is to be done from the user's main account without privileges.

evidence an assessor asks for List of dedicated admin accounts separate from users' everyday accounts; Privilege review showing everyday accounts hold no administrator rights; Membership exports of privileged groups showing only admin-designated accounts; Policy settings blocking email and web browsing for administrator accounts; Sample of administrators showing a separate standard account used for daily work

PR.AA-05
NIST CSF 2.0

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

evidence an assessor asks for Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records

23 NYCRR 500, when it applies

Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.

ClauseThe held text, and the evidence an assessor asks for
500.7
23 NYCRR 500 (add-on)
Access Privileges and Management

Limit user access privileges to Nonpublic Information based on least privilege, limit privileged accounts, periodically review access (at least annually), promptly terminate access on role change or separation, disable or securely configure remote access, implement password policy aligned with industry standards. Class A must implement privileged access management and prohibit commonly used passwords.

evidence an assessor asks for Access control policy with least privilege standard; Privileged account inventory and PAM tooling for Class A; Annual user access reviews with attestations; Joiners movers leavers process with timing metrics; Password policy aligned to NIST or equivalent; Banned password list enforcement (Class A); Remote access architecture and MFA evidence

In United Kingdom

ClauseThe held text, and the evidence an assessor asks for
CE-AC.5
Cyber Essentials
Separate Admin Accounts for Administrative Activities

Use separate accounts to perform administrative activities only. Admin accounts must not be used for routine activities like email and web browsing.

evidence an assessor asks for named admin accounts (e.g. adm-jdoe); conditional access blocking email/web for admin accounts

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.2
ISO/IEC 27001:2022 (lens)
Privileged access rights

The granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2.

evidence an assessor asks for Statement of Applicability entry for control A.8.2, showing inclusion or justified exclusion, implementation status and the risks it treats; An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry; Privileged access management configuration showing time-limited elevation, step-up authentication and session recording; Privileged access review records performed periodically and after organizational changes

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule