NIST 800-53 Rev. 5

AC-6(3): Least Privilege | Network Access to Privileged Commands

Control Text:

Authorize network access to [Assignment: organization-defined privileged commands] only for [Assignment: organization-defined compelling operational needs] and document the rationale for such access in the security plan for the system.

Network access is any access across a network connection in lieu of local access (i.e., user being physically present at the device).

Related Controls