Почему это важно
Разделение снижает риск fraud, ошибки и сокрытия следов, особенно для access grants, secrets, backups и audit controls.
Что подтверждено
NIST AC-5 требует разделять duties разных individuals и документировать responsibilities, которым нужно такое разделение.
Граница применимости: NIST SP 800-53 Rev. 5 separation-of-duties control.
Два человека с одним shared admin credential не создают separation of duties, потому что действия неразличимы и оба имеют одинаковую end-to-end privilege.
Граница применимости: Accountability and privilege separation.
Что проверить
- Разделите request и approval.
- Используйте distinct identities.
- Проверьте конфликтующие roles.
Первоисточники
Security and Privacy Controls for Information Systems and Organizations
National Institute of Standards and Technology · NIST SP 800-53 Rev. 5, Release 5.2.0
Содержит controls для authorization, least privilege, separation of duties, privileged functions и protection of audit information.
Открыть первоисточникIdentity and Access Management: Recommended Best Practices for Administrators
Cybersecurity and Infrastructure Security Agency · CISA and NSA Enduring Security Framework guidance, December 2023
Связывает privileged identities с PAM, strong identity controls, auditing и ограничением administrative access.
Открыть первоисточник