Break Glass Account
What is Break Glass Account?
An emergency access account that bypasses normal access controls during critical situations, with strict monitoring and post-use review procedures.
Frameworks that govern break glass account
What the standards actually require on break glass account
Requirements naming break glass account across 4 standards, quoted from the control text.
Break glass accounts are only used when normal authentication processes cannot be used.
ISM-1611 · Break glass accounts are only used when normal authentication processes cannot be used. →All ML1 requirements plus: Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated. Privileged access to systems and applications is disabled after 45 days of inactivity.
E8-ADMIN-ML2 · Restrict Administrative Privileges (ML2) →Establish procedures for obtaining necessary ePHI during an emergency. NIST recommends break-glass accounts, time-bounded activation, and full logging.
164.312(a)(2)(ii) · Emergency Access Procedure (Required) →Establish procedures for obtaining necessary ePHI during an emergency. NIST recommends break-glass accounts, time-bounded activation, and full logging.
164.312(a)(2)(ii) · Emergency Access Procedure (Required) →Questions people ask about break glass account
What is Break Glass Account?
Why is Break Glass Account important for compliance?
Which compliance frameworks address Break Glass Account?
Where can I learn more about Break Glass Account?
See how Break Glass Account applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.