Skip to main content

ER-37 Walkthrough - Privileged Access to the Production Network

Suzette Richards avatar
Written by Suzette Richards
Updated over a month ago

Evidence of All Privileged Access to the Production Network

Provide system screenshots or a system-generated list of users who have access privileges to the production network, including users who can:

  • Add, modify, or delete users or access to in-scope production resources

  • Add, modify, or delete production assets

Evidence of All Privileged Users to VPN (if applicable)

If you use a VPN, provide system screenshots or a system-generated list of users with access privileges to the VPN.

Additional Guidance

As a best practice, privileged access to production systems should be limited.

Privileged access should be granted to individuals based on their job role and responsibilities.

Your production network is where the production assets reside. These assets are used to provide your in-scope service and are where customer data resides.

If your service uses a CSP, the production network is covered by the Cloud Console request.

Related Articles

Associated Unified Control ID

Associated Framework Control

CTRL-9

LCL-32

Did this answer your question?