FedRAMP Controls / AC

AC-6 Least Privilege

Family AC
Baselines moderate
Mapped KSIs 2

Control statement

Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-IAM-04Just-in-Time Authorization
Use a least-privileged, role and attribute-based, and just-in-time security authorization model for all user and non-user accounts and services.
Identity and Access Management
KSI-IAM-05Least Privilege
_Persistently_ ensure that identity and access management employs measures to ensure each user or device can only access the resources they need.
Identity and Access Management