Skip to main content

ER-40 Walkthrough - Privileged Access to the Data Stores

Suzette Richards avatar
Written by Suzette Richards
Updated over a month ago

Evidence of All Privileged Users with Datastore Access

Provide system screenshots or a system-generated list of users who have access privileges to alter in-scope production system data, data stores, and users.

For each in-scope production system, the evidence should demonstrate who can:

  • Add, modify, or delete data

  • Add, modify, or delete data stores

  • Add other privileged users

  • SSH into databases and execute privileged commands

Related Articles

Example Evidence

MongoDB Atlas

Associated Unified Control ID

Associated Framework Control

CTRL-9

LCL-32

Did this answer your question?