ASOM-Fedv6.1Open the explorer
WF-2 · Workforce Terrain

Privileged Human Register

Control Statement

Every privileged account shall resolve to a named, currently employed, appropriately vetted individual, and the register shall be reconciled on a defined cadence.

Purpose. To ensure privilege is held by accountable people, so that every privileged action has a person behind it.

Discussion

Three failure classes hide behind an apparently clean privileged account list: accounts bound to departed staff, accounts bound to nobody at all — shared, service, or legacy — and accounts bound to people whose vetting no longer covers the access they hold. The reconciliation cadence catches the first, the resolution requirement catches the second, and the vetting check catches the third, which is the one most often missed because it fails silently as access accumulates around a person who was correctly cleared for their original role.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Every privileged account resolves to a named current individual.
  • Number of privileged accounts not resolving to a named individual
  • Number resolving to an individual who has left or changed role
Reconciliation happens on cadence.
  • Elapsed time since the last register reconciliation

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Bind every privileged account to a named individual.
  2. L2Raise a finding for privileged accounts that resolve to no named holder.
  3. L2Reconcile the register against the identity provider on a defined cadence.
  4. L3Verify that each named holder is currently employed or under current contract, reconciled against the personnel record.
  5. L3Verify that each holder's vetting covers the access currently held, not the access held when they were vetted.
  6. L3Record shared, service and non-human accounts distinctly, each with a named accountable human owner, rather than treating them as exceptions to the register.
  7. L3Record and time-bound justified exceptions rather than allowing them to persist unmarked.
  8. L4Measure accumulated privilege per holder over time, since the common failure is entitlement growth around a correctly vetted person rather than an improperly granted account.
  9. L4Trend the count of unresolved and exception accounts, driving both toward zero.
  10. L5Drive privilege toward just-in-time issuance where the platform supports it, so the register shrinks rather than being reconciled more often.

Measurement

Outcome

Percentage of privileged accounts resolving to a current, adequately vetted named individual.

Performance

Accumulated privilege per holder, trended.

Evidence and Assessment

Evidence expected

Privileged human register with reconciliation dates; exception list with justification and expiry; vetting adequacy records.

Assessment procedure

Examine the register against the identity provider; test a sample of privileged accounts for a current, vetted holder; test whether vetting covers the access currently held rather than the access originally granted.

Related Guidance

Inherits
  • PS-3
  • AC-2(7)
  • IA-2(1)
Satisfies
  • PR.AA-05
  • GV.RR-02

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.2 of 20 techniques — M3.19, M3.20
  • M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.12
  • M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.16

Terrain It Is Named On

  • T1IdentityThe privileged human register on T7 and the privileged account inventory here are two views of one population; reconciling them is what finds the accounts with no human behind them.
  • T7WorkforceThe privileged human register, which is the decisive point on this layer stated as a control.

Artifacts It Stands On

  • producesPrivileged human registerWhich individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet.
  • consumesWorkforce terrain registerThe roles whose compromise is equivalent to compromising a decisive point — the operators of decisive points, and the roles with standing access to them.

Roles It Puts to Work