answersLogoWhite

0

The best answer is probably to flip the question around to ask when it is acceptable to NOT use a non-privileged account.

A non-privileged account should always be used except when it is absolutely necessary (and authorized) to use the permissions assigned to a privileged account. Only those acting as system administrators or system auditors should ever have privileged accounts and they should only use those accounts when the actions they are performing required the elevated privileges assigned to the privileged account. They should be assigned and use non-privileged accounts for all other actions.

Section 3-3 a.(13) states that privileged users must:

(13) Maintain and use at least 2 separate accounts for access to network resources, 1 for their privileged level access and a separate general user, non-privileged level account for routine procedures.

Section 4.5 c. states:

c. Access control. IA personnel will implement system and device access controls using the principle of least privilege (POLP) via automated or manual means to actively protect the IS from compromise, unauthorized use or access, and manipulation.

One consequence of this is that they are required to always implement non-privileged accounts except where elevated privileges are required.

User Avatar

Wiki User

13y ago

What else can I help you with?

Trending Questions
Salary of wbcs officers ofter 6th pay commission? Who investigates criminal activities for the us department of justice? What agency of the government should I contact to protect your ownership of the idea of my invention? What is reverse 911 phone calls? What is required to form an agency? FBI showed up to my house a few weeks ago and I have not been charged? How can law enforcement officers get past their fear of litigation How can those who employ police officers help in this effort? What firearm do police mostly carry? How do incident investigation reports help other organizations to improve their safety programs? What is the eclectic nature of public administration? What training is required of a security guard? What is the difference in a county police officer and a state trooper in s.c.? Can an inmate in reception at stateville correctional center receive mail or has an address where letters can be sent? Which federal regulatory agency would investigate the claim of hazardous working conditions? Does big ben have a prison room? In what DoD Directive would you find guidance for the training certifications and workforce management of the DoD Information Assurance workforce? Are there any job opportunities for retired police officers in Miami? What is the federal agency that mandates local establishments to keep an SDS on file for each chemical? What is jurisdictional autonomy dealing with emergency management? Most of the money spent for prisons is used for?