Skip to main content

ER-40 Pre-Kickoff - Privileged Access to the Data Stores

Suzette Richards avatar
Written by Suzette Richards
Updated this week

Evidence of All Privileged Users with Datastore Access

Provide system screenshots or a system-generated list of users who have access privileges to alter in-scope production system data, data stores, and users.

For each in-scope production system, the evidence should demonstrate who can:

  • Add, modify, or delete data

  • Add, modify, or delete data stores

  • Add other privileged users

  • SSH into databases and execute privileged commands

Related Articles

Example Evidence

MongoDB Atlas

Associated Unified Control ID

Associated Framework Control

CTRL-9

REQ-28

Did this answer your question?