ADMIN-ML2 Restrict Administrative Privileges (ML2)
All ML1 requirements plus: Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated. Privileged access to systems and applications is disabled after 45 days of inact
8
artefacts
4
held by a system
0
at each review
easy
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Sample audit log of disabled accounts with reason (inactivity vs revocation) · Identity provider / directory
- Credential vault (CyberArk, BeyondTrust, HashiCorp Vault, Entra ID password rotation) configuration evidence · Identity provider / directory
- SIEM use case for privileged logon, group membership change, AdminSDHolder modification, golden ticket markers · Identity provider / directory
- Log integrity evidence (Azure Monitor immutable, WORM, separation of duties) · SIEM / log platform
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Identity governance workflow (SailPoint, Saviynt, Entra ID PIM) showing 12-month revalidation and 45-day inactivity disablement · Document repository
- Jump server architecture diagram and access policy: admins cannot RDP directly to managed servers, must go via bastion · Policy repository / GRC workspace
- Privileged Access Workstation policy showing it is not a VM inside a regular workstation · Policy repository / GRC workspace
- Break-glass account procedure with seal logs and last access date · Policy repository / GRC workspace
First move
Automate the pull from your Identity provider / directory. Scheduled export of users, roles and MFA state from the directory; access-review completion pulled from the IdP, not a spreadsheet.
Common gaps auditors find
- Revalidation done annually but no automated disablement, manual list maintained
- Inactivity threshold tracked but service accounts excluded entirely
- Jump servers exist but bypass paths allowed (direct RDP for break-glass scenarios uncontrolled)
- Local admin passwords managed by LAPS on workstations but not on servers
- Service account passwords static for years, no rotation
- Privileged events logged but log management is itself controlled by the same admins
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetADMIN-ML1 Restrict Administrative Privileges (ML1) · ADMIN-ML3 Restrict Administrative Privileges (ML3)