CYB-14 · Cyber security
Local and global admin accounts represent the highest-value target for attackers. Privileged accounts must be: minimised (least privilege principle), named to individuals (no shared admin accounts), MFA-enforced, and reviewed quarterly. Break-glass emergency accounts must be sealed and audited.
Trigger
Shared admin accounts in use; privileged accounts not reviewed in last 6 months; admin accounts used for day-to-day tasks; no record of who holds elevated privileges
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Audit all privileged accounts. Remove shared admin credentials. Assign named admin accounts with MFA. Implement quarterly access review. Separate admin accounts from daily-use accounts (dedicated admin UPN).
Evidence required