NIST Special Publication 800-171 Revision 2

Date Published: January 28th, 2021

Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3

Author(s): Ron Ross (NIST), Victoria Pillitteri (NIST), Kelley Dempsey (NIST), Mark Riddle (NARA), Gary Guissanie (IDA)

Note: A Class Deviation is in effect as of May 2, 2024 (DEVIATION 2024O0013). The deviation clause requires contractors, who are subject to 252.204-7012, to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. Click Here

3.1.5 Employ the principle of least privilege, including for
specific security functions and privileged accounts.

Control Family: Access Control

Control Type: Derived

SPRS Value: 1

CMMC Level(s): AC.L2-3.1.5

Top Ten Failed Requirement: No

DIBCAC HIGH Failure Rate (OTS):

44th of 110

Referenced in:

DFARS 252.204-7012

Derived From: NIST SP 800-53r4

  • AC-6

  • AC-6(1)

  • AC-6(5)

CSF v1.1:

  • PR.AC-4

NIST 800-171 Control 3.1.5 MITRE ATT&CK 14.1 Sunburst

NIST SP 800-171r2 Control 3.1.5 → MITRE ATT&CK 14.1

Mapping note: MITRE ATT&CK 14.1 techniques are derived through the NIST SP 800-53 Rev. 4 controls mapped to each NIST SP 800-171 Rev. 2 requirement.

Summary

  • Total mappings: 240
  • Families: 1
  • Outer ring: Technique ID + name
  • MITRE ATT&CK version: 14.1

Family counts

  • Least Privilege: 240 techniques

Usage notes

  • Click a family or technique to zoom in.
  • Click the center to zoom back out.
  • Hover to view technique details.

Discussion:

Organizations employ the principle of least privilege for specific duties and authorized accesses for users and processes. The principle of least privilege is applied with the goal of authorized privileges no higher than necessary to accomplish required organizational missions or business functions. Organizations consider the creation of additional processes, roles, and system accounts as necessary, to achieve least privilege. Organizations also apply least privilege to the development, implementation, and operation of organizational systems. Security functions include establishing system accounts, setting events to be logged, setting intrusion detection parameters, and configuring access authorizations (i.e., permissions, privileges). Privileged accounts, including super user accounts, are typically described as system administrator for various types of commercial off-the-shelf operating systems. Restricting privileged accounts to specific personnel or roles prevents day-to-day users from having access to privileged information or functions. Organizations may differentiate in the application of this requirement between allowed privileges for local accounts and for domain accounts provided organizations retain the ability to control system configurations for key security parameters and as otherwise necessary to sufficiently mitigate risk.

Determining Statements (NIST SP 800-171Ar2)

Upon assessment, assessors must determine if-

3.1.5[a] privileged accounts are identified.
3.1.5[b] access to privileged accounts is authorized in accordance with the principle of
least privilege.
3.1.5[c] security functions are identified.
3.1.5[d] access to security functions is authorized in accordance with the principle of
least privilege.

Assessors are instructed to-

Examine: [SELECT FROM: Access control policy; procedures addressing account management; system security plan; system design documentation; system configuration settings and associated documentation; list of active system accounts and the name of the individual associated with each account; list of conditions for group and role membership; notifications or records of recently transferred, separated, or terminated employees; list of recently disabled system accounts along with the name of the individual associated with each account; access authorization records; account management compliance reviews; system monitoring/audit records; procedures addressing least privilege; list of security functions (deployed in hardware, software, and firmware) and security-relevant information for which access is to be explicitly authorized; list of system-generated privileged accounts; list of system administration personnel; other relevant documents or records].

Interview: [SELECT FROM: Personnel with account management responsibilities; system or network administrators; personnel with information security responsibilities; personnel with responsibilities for defining least privileges necessary to accomplish specified tasks].

Test: [SELECT FROM: Organizational processes for managing system accounts; mechanisms for implementing account management; mechanisms implementing least privilege functions; mechanisms prohibiting privileged access to the system].

FURTHER DISCUSSION

The principle of least privilege applies to all users and processes on all systems, but it is critical to systems containing or accessing CUI. Least privilege:

  • restricts user access to only the machines and information needed to fulfill job responsibilities; and

  • limits what system configuration settings users can change, only allowing individuals with a business need to change only allowing individuals with a business need to change them.

Example

You create accounts for an organization that processes CUI. By default, everyone is assigned a basic user role, which prevents a user from modifying system configurations. Privileged access is only assigned to users and processes that require it to carry out job functions, such as IT staff, and is very selectively granted [b,d].

Potential Assessment Considerations

  • Are privileged accounts documented and is when they may be used defined [a]?

  • Are users assigned privileged accounts to perform their job functions only when it is necessary [b]?

  • Are necessary security functions identified (e.g., access control configuration, system configuration settings, or privileged account lists) that must be managed through the use of privileged accounts [c]? 20 NIST SP 800-171 Rev. 2, p. 12. AC.L2-3.1.5 – Least Privilege CMMC Assessment Guide – Level 2 | Version 2.13 26

  • Is access to privileged functions and security information restricted to authorized employees [d]?

ISO/IEC 27001:2013

A.9.1.2 Access to networks and network services

A.9.2.3 Management of privileged access rights

A.9.4.4 Use of privileged utility programs

A.9.4.5 Access control to program source code

NIST SP 800-171r2 Control 3.1.5 → MITRE ATT&CK
MITRE ATT&CK v14.1

NIST SP 800-171r2 Control 3.1.5 → MITRE ATT&CK 14.1

Total Mappings

240
technique references

Families

1
Least Privilege

Control

3.1.5
AC.L2-3.1.5

Least Privilege 240 techniques

  • T1003OS Credential Dumping
  • T1003.001LSASS Memory
  • T1003.002Security Account Manager
  • T1003.003NTDS
  • T1003.004LSA Secrets
  • T1003.005Cached Domain Credentials
  • T1003.006DCSync
  • T1003.007Proc Filesystem
  • T1003.008/etc/passwd and /etc/shadow
  • T1005Data from Local System
  • T1021Remote Services
  • T1021.001Remote Desktop Protocol
  • T1021.002SMB/Windows Admin Shares
  • T1021.003Distributed Component Object Model
  • T1021.004SSH
  • T1021.005VNC
  • T1021.006Windows Remote Management
  • T1025Data from Removable Media
  • T1036Masquerading
  • T1036.003Rename System Utilities
  • T1036.005Match Legitimate Name or Location
  • T1041Exfiltration Over C2 Channel
  • T1047Windows Management Instrumentation
  • T1048Exfiltration Over Alternative Protocol
  • T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
  • T1048.003Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • T1052Exfiltration Over Physical Medium
  • T1052.001Exfiltration over USB
  • T1053Scheduled Task/Job
  • T1053.002At (Windows)
  • T1053.003Cron
  • T1053.005Scheduled Task
  • T1053.006Systemd Timers
  • T1053.007Container Orchestration Job
  • T1055Process Injection
  • T1055.001Dynamic-link Library Injection
  • T1055.002Portable Executable Injection
  • T1055.003Thread Execution Hijacking
  • T1055.004Asynchronous Procedure Call
  • T1055.005Thread Local Storage
  • T1055.008Ptrace System Calls
  • T1055.009Proc Memory
  • T1055.011Extra Window Memory Injection
  • T1055.012Process Hollowing
  • T1055.013Process Doppelgänging
  • T1055.014VDSO Hijacking
  • T1056.003Web Portal Capture
  • T1059Command and Scripting Interpreter
  • T1059.001PowerShell
  • T1059.002AppleScript
  • T1059.003Windows Command Shell
  • T1059.004Unix Shell
  • T1059.005Visual Basic
  • T1059.006Python
  • T1059.007JavaScript
  • T1059.008Network Device CLI
  • T1068Exploitation for Privilege Escalation
  • T1070Indicator Removal on Host
  • T1070.001Clear Windows Event Logs
  • T1070.002Clear Linux or Mac System Logs
  • T1070.003Clear Command History
  • T1070.007Clear Network Connection History and Configurations
  • T1070.008Clear Mailbox Data
  • T1070.009Clear Persistence
  • T1072Software Deployment Tools
  • T1078Valid Accounts
  • T1078.001Default Accounts
  • T1078.002Domain Accounts
  • T1078.003Local Accounts
  • T1078.004Cloud Accounts
  • T1087.004Cloud Account
  • T1091Replication Through Removable Media
  • T1098Account Manipulation
  • T1098.001Additional Cloud Credentials
  • T1098.002Exchange Email Delegate Permissions
  • T1098.003Add Office 365 Global Administrator Role
  • T1098.004SSH Authorized Keys
  • T1098.005Device Registration
  • T1106Native API
  • T1110Brute Force
  • T1110.001Password Guessing
  • T1110.002Password Cracking
  • T1110.003Password Spraying
  • T1110.004Credential Stuffing
  • T1112Modify Registry
  • T1133External Remote Services
  • T1134Access Token Manipulation
  • T1134.001Token Impersonation/Theft
  • T1134.002Create Process with Token
  • T1134.003Make and Impersonate Token
  • T1134.005SID-History Injection
  • T1136Create Account
  • T1136.001Local Account
  • T1136.002Domain Account
  • T1136.003Cloud Account
  • T1137Office Application Startup
  • T1137.001Office Template Macros
  • T1137.002Office Test
  • T1137.003Outlook Forms
  • T1137.004Outlook Home Page
  • T1137.005Outlook Rules
  • T1137.006Add-ins
  • T1176Browser Extensions
  • T1185Browser Session Hijacking
  • T1189Drive-by Compromise
  • T1190Exploit Public-Facing Application
  • T1197BITS Jobs
  • T1199Trusted Relationship
  • T1200Hardware Additions
  • T1203Exploitation for Client Execution
  • T1210Exploitation of Remote Services
  • T1211Exploitation for Defense Evasion
  • T1212Exploitation for Credential Access
  • T1213Data from Information Repositories
  • T1213.001Confluence
  • T1213.002Sharepoint
  • T1213.003Code Repositories
  • T1218Signed Binary Proxy Execution
  • T1218.007Msiexec
  • T1222File and Directory Permissions Modification
  • T1222.001Windows File and Directory Permissions Modification
  • T1222.002Linux and Mac File and Directory Permissions Modification
  • T1484Domain Policy Modification
  • T1485Data Destruction
  • T1486Data Encrypted for Impact
  • T1489Service Stop
  • T1490Inhibit System Recovery
  • T1491Defacement
  • T1491.001Internal Defacement
  • T1491.002External Defacement
  • T1495Firmware Corruption
  • T1505Server Software Component
  • T1505.002Transport Agent
  • T1505.003Web Shell
  • T1505.004IIS Components
  • T1505.005Terminal Services DLL
  • T1525Implant Internal Image
  • T1528Steal Application Access Token
  • T1530Data from Cloud Storage Object
  • T1537Transfer Data to Cloud Account
  • T1538Cloud Service Dashboard
  • T1539Steal Web Session Cookie
  • T1542Pre-OS Boot
  • T1542.001System Firmware
  • T1542.003Bootkit
  • T1542.004ROMMONkit
  • T1542.005TFTP Boot
  • T1543Create or Modify System Process
  • T1543.001Launch Agent
  • T1543.002Systemd Service
  • T1543.003Windows Service
  • T1543.004Launch Daemon
  • T1546.003Windows Management Instrumentation Event Subscription
  • T1546.004Unix Shell Configuration Modification
  • T1546.011Application Shimming
  • T1546.013PowerShell Profile
  • T1546.016Installer Packages
  • T1547.003Time Providers
  • T1547.004Winlogon Helper DLL
  • T1547.006Kernel Modules and Extensions
  • T1547.009Shortcut Modification
  • T1547.012Print Processors
  • T1547.013XDG Autostart Entries
  • T1548Abuse Elevation Control Mechanism
  • T1548.002Bypass User Account Control
  • T1548.003Sudo and Sudo Caching
  • T1550Use Alternate Authentication Material
  • T1550.002Pass the Hash
  • T1550.003Pass the Ticket
  • T1552Unsecured Credentials
  • T1552.001Credentials In Files
  • T1552.002Credentials in Registry
  • T1552.006Group Policy Preferences
  • T1552.007Container API
  • T1553Subvert Trust Controls
  • T1553.003SIP and Trust Provider Hijacking
  • T1553.006Code Signing Policy Modification
  • T1556Modify Authentication Process
  • T1556.001Domain Controller Authentication
  • T1556.003Pluggable Authentication Modules
  • T1556.004Network Device Authentication
  • T1556.005Reversible Encryption
  • T1556.006Multi-Factor Authentication
  • T1556.007Hybrid Identity
  • T1558Steal or Forge Kerberos Tickets
  • T1558.001Golden Ticket
  • T1558.002Silver Ticket
  • T1558.003Kerberoasting
  • T1559Inter-Process Communication
  • T1559.001Component Object Model
  • T1559.002Dynamic Data Exchange
  • T1561Disk Wipe
  • T1561.001Disk Content Wipe
  • T1561.002Disk Structure Wipe
  • T1562Impair Defenses
  • T1562.001Disable or Modify Tools
  • T1562.002Disable Windows Event Logging
  • T1562.004Disable or Modify System Firewall
  • T1562.006Indicator Blocking
  • T1562.007Disable or Modify Cloud Firewall
  • T1562.008Disable Cloud Logs
  • T1562.009Safe Mode Boot
  • T1563Remote Service Session Hijacking
  • T1563.001SSH Hijacking
  • T1563.002RDP Hijacking
  • T1567Exfiltration Over Web Service
  • T1569System Services
  • T1569.001Launchctl
  • T1569.002Service Execution
  • T1574Hijack Execution Flow
  • T1574.004Dylib Hijacking
  • T1574.005Executable Installer File Permissions Weakness
  • T1574.007Path Interception by PATH Environment Variable
  • T1574.008Path Interception by Search Order Hijacking
  • T1574.009Path Interception by Unquoted Path
  • T1574.010Services File Permissions Weakness
  • T1574.011Services Registry Permissions Weakness
  • T1574.012COR_PROFILER
  • T1578Modify Cloud Compute Infrastructure
  • T1578.001Create Snapshot
  • T1578.002Create Cloud Instance
  • T1578.003Delete Cloud Instance
  • T1580Cloud Infrastructure Discovery
  • T1599Network Boundary Bridging
  • T1599.001Network Address Translation Traversal
  • T1601Modify System Image
  • T1601.001Patch System Image
  • T1601.002Downgrade System Image
  • T1606Forge Web Credentials
  • T1606.001Web Cookies
  • T1606.002SAML Tokens
  • T1609Container Administration Command
  • T1610Deploy Container
  • T1611Escape to Host
  • T1612Build Image on Host
  • T1613Container and Resource Discovery
  • T1619Cloud Storage Object Discovery
  • T1621Multi-Factor Authentication Request Generation
  • T1647Plist File Modification
  • T1648Serverless Execution

Frameworks & Controls