EvidenceSheet

ADMIN-ML2 Restrict Administrative Privileges (ML2)

All ML1 requirements plus: Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated. Privileged access to systems and applications is disabled after 45 days of inact

8
artefacts
4
held by a system
0
at each review
easy
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Sample audit log of disabled accounts with reason (inactivity vs revocation) · Identity provider / directory
  • Credential vault (CyberArk, BeyondTrust, HashiCorp Vault, Entra ID password rotation) configuration evidence · Identity provider / directory
  • SIEM use case for privileged logon, group membership change, AdminSDHolder modification, golden ticket markers · Identity provider / directory
  • Log integrity evidence (Azure Monitor immutable, WORM, separation of duties) · SIEM / log platform

periodic reviewEvidence produced at each review

none for this control

governing documentDocuments that govern the control

  • Identity governance workflow (SailPoint, Saviynt, Entra ID PIM) showing 12-month revalidation and 45-day inactivity disablement · Document repository
  • Jump server architecture diagram and access policy: admins cannot RDP directly to managed servers, must go via bastion · Policy repository / GRC workspace
  • Privileged Access Workstation policy showing it is not a VM inside a regular workstation · Policy repository / GRC workspace
  • Break-glass account procedure with seal logs and last access date · Policy repository / GRC workspace

First move

Automate the pull from your Identity provider / directory. Scheduled export of users, roles and MFA state from the directory; access-review completion pulled from the IdP, not a spreadsheet.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

ADMIN-ML1 Restrict Administrative Privileges (ML1) · ADMIN-ML3 Restrict Administrative Privileges (ML3)