Evidence of All Privileged Access to the Production Network
Provide system screenshots or a system-generated list of users who have access privileges to the production network, including users who can:
Add, modify, or delete users or access to in-scope production resources
Add, modify, or delete production assets
Evidence of All Privileged Users to VPN (if applicable)
If you use a VPN, provide system screenshots or a system-generated list of users with access privileges to the VPN.
Additional Guidance
As a best practice, privileged access to production systems should be limited.
Privileged access should be granted to individuals based on their job role and responsibilities.
Your production network is where the production assets reside. These assets are used to provide your in-scope service and are where customer data resides.
If your service uses a CSP, the production network is covered by the Cloud Console request.
Related Articles
Associated Unified Control ID | Associated Framework Control |
CTRL-9 | LCL-32 |