FedRAMP Controls / AC

AC-2(7) Privileged User Accounts

Family AC
Baselines moderate
Mapped KSIs 0

Control statement

(a) Establish and administer privileged user accounts in accordance with {{ insert: param, ac-02.07_odp }};
    (b) Monitor privileged role or attribute assignments;
    (c) Monitor changes to roles or attributes; and
    (d) Revoke access when privileged role or attribute assignments are no longer appropriate.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

No 20x Key Security Indicators map to this control in the current catalog version.