Control Statement
Every privileged account shall resolve to a named, currently employed, appropriately vetted individual, and the register shall be reconciled on a defined cadence.
Purpose. To ensure privilege is held by accountable people, so that every privileged action has a person behind it.
Discussion
Three failure classes hide behind an apparently clean privileged account list: accounts bound to departed staff, accounts bound to nobody at all — shared, service, or legacy — and accounts bound to people whose vetting no longer covers the access they hold. The reconciliation cadence catches the first, the resolution requirement catches the second, and the vetting check catches the third, which is the one most often missed because it fails silently as access accumulates around a person who was correctly cleared for their original role.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of privileged accounts not resolving to a named individual
- Number resolving to an individual who has left or changed role
- Elapsed time since the last register reconciliation
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- WF-1 Workforce Terrain IdentificationIdentified high-consequence roles
- Outside the frameworkIdentity system account data, HR records and vetting status
- WF-5 Separation and Revocation TempoRegister update following removal
Produces
- WF-5 Separation and Revocation TempoRegister against which separation and revocation is executed
- TM-7 Terrain OwnershipOwnership verification for terrain elements
- CE-5 Remediation Backlog PrioritizationUnresolved accounts entering the backlog
- WF-4 Insider Risk PositionPrivileged human register
- ID-2 Credential Strength and BindingPrivileged human register, to match proofing to privilege
Activities
- L2Bind every privileged account to a named individual.
- L2Raise a finding for privileged accounts that resolve to no named holder.
- L2Reconcile the register against the identity provider on a defined cadence.
- L3Verify that each named holder is currently employed or under current contract, reconciled against the personnel record.
- L3Verify that each holder's vetting covers the access currently held, not the access held when they were vetted.
- L3Record shared, service and non-human accounts distinctly, each with a named accountable human owner, rather than treating them as exceptions to the register.
- L3Record and time-bound justified exceptions rather than allowing them to persist unmarked.
- L4Measure accumulated privilege per holder over time, since the common failure is entitlement growth around a correctly vetted person rather than an improperly granted account.
- L4Trend the count of unresolved and exception accounts, driving both toward zero.
- L5Drive privilege toward just-in-time issuance where the platform supports it, so the register shrinks rather than being reconciled more often.
Measurement
Percentage of privileged accounts resolving to a current, adequately vetted named individual.
Accumulated privilege per holder, trended.
Evidence and Assessment
Privileged human register with reconciliation dates; exception list with justification and expiry; vetting adequacy records.
Examine the register against the identity provider; test a sample of privileged accounts for a current, vetted holder; test whether vetting covers the access currently held rather than the access originally granted.
Related Guidance
- PS-3
- AC-2(7)
- IA-2(1)
- PR.AA-05
- GV.RR-02
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.2 of 20 techniques — M3.19, M3.20
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.12
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.16
Terrain It Is Named On
Artifacts It Stands On
- producesPrivileged human registerWhich individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet.
- consumesWorkforce terrain registerThe roles whose compromise is equivalent to compromising a decisive point — the operators of decisive points, and the roles with standing access to them.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.