Administrative Access
What is Administrative Access?
Elevated system privileges that allow users to perform configuration changes, install software, and manage other user accounts on a system.
Terms that appear alongside administrative access
Each of these is named in at least one of the same controls as administrative access. The number is how many controls name both.
- authentication 10 shared controls
- access management 9 shared controls
- multi factor authentication 7 shared controls
- privileged access management 7 shared controls
- access control 6 shared controls
- encryption 4 shared controls
- role based access control 4 shared controls
- remote access 4 shared controls
Frameworks that govern administrative access
What the standards actually require on administrative access
Requirements naming administrative access across 6 standards, quoted from the control text.
Require MFA for all administrative access accounts, where supported, on all enterprise assets, whether managed on-site or through a third-party provider.
CIS-6.5 · Require MFA for Administrative Access →MFA is implemented for all non-console access into the CDE for personnel with administrative access
8.4.1 · MFA is implemented for all non-console access into the CDE for personnel with administrative access →Operations and management interfaces to 5G NFs must be authenticated, encrypted, and logged. Administrative access requires strong authentication, role separation, and privileged access management.
33.501-OAM · Management Plane Security →ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →Kuwait KDPPR Articles 4-5 mandate appropriate technical + organisational security measures proportionate to risk + nature of Personal Data + processing operations.
KDPPR-Information-Security-Controls-Encryption-Access-Control-Logging-Monitoring-Article-4-5 · Kuwait KDPPR Information Security Controls + Encryption + Access Control + Logging + Monitoring →Implement NIST 800-53 AC Access Control family + IA Identification and Authentication family per MARS-E v2.0 catalog. NIST 800-63-3 Identity Assurance Level 2 (IAL2) + Authenticator Assurance Level 2 (AAL2) + Federation Assurance Level 2 (FAL2) for Exchange co...
MARS-E-Access-Control-Identity-Authentication-NIST-800-63-Identity-Assurance-Levels-MFA-AC-IA-Families · MARS-E Access Control + Identity + Authentication + NIST 800-63 + MFA + AC + IA Families →Questions people ask about administrative access
What is Administrative Access?
Why is Administrative Access important for compliance?
Which compliance frameworks address Administrative Access?
Where can I learn more about Administrative Access?
See how Administrative Access applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.