What to Provide
A screenshot demonstrating all users with privileged access to the production network.
Evidence Format
Screenshots or exported images in a common image file type such as .jpg, .png, or .pdf.
Additional Guidance
This evidence should demonstrate all users who can:
Add, modify, or delete users or access to in-scope production resources
Add, modify, or delete production assets
As a best practice, privileged access to production systems should be limited.
Privileged access should be granted to individuals based on their job role and responsibilities.
Your production network is where the production assets reside. These assets are used to provide your in-scope service and are where customer data resides.
If your service uses a CSP, please mark this ER as N/A, as the production network is covered by the Cloud Console request (ER-41).
Related Articles
Associated Unified Control ID | Associated Framework Control |
CTRL-9 | LCL-32 |