← ISO 27001 · A.8 — Technological
A.8.2 — Privileged access rights
critical
privileged-accessaccess-control
Requirement
The allocation and use of privileged access rights shall be restricted and managed.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
privilegedadminadministratorrootelevatedadministrative
Required element 2 — any one of
restrictlimitedapprovaljust-in-timeseparate accountreviewapprove
Supporting terms — specificity signals
pambreak glasssession recordingsudotime-boundmfa required
Contradiction markers
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
everyone is an admin
shared root account
no privileged access control
everyone has admin
all users are administrators
all users have admin
shared admin
shared administrator account
shared root
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| HIPAA | 164.308(a)(3)(ii)(A) | Authorisation and supervision (A) | access-control privileged-access |
| NIST CSF 2.0 | PR.AA-05 | Access permissions follow least privilege and separation of duties | access-control privileged-access |
| GDPR | Art.29 | Processing under the authority of the controller | access-control |
| CCPA/CPRA | 1798.100(e) & 1798.150 | Reasonable security procedures | access-control |
| SOC 2 | CC6.2 | Registration and authorisation of new users | access-control |
| PCI DSS 4.0.1 | 7.2 | Access granted by least privilege and reviewed every six months | access-control |
| PCI DSS 4.0.1 | 8.2 | Unique IDs and user account lifecycle | access-control |
| PCI DSS 4.0.1 | 8.6 | System and application accounts are managed | privileged-access |