Access Control (AC)
Account management, least privilege, separation of duties and session control.
- Account management
- Least privilege
- Separation of duties
The most granular control catalogue most programmes will ever import, which is exactly why it belongs in a library that maps controls to one another. Import it once and let ISO/IEC 27001, CSF functions and your own standard reference it rather than restate it.
Published by the National Institute of Standards and Technology. Used well beyond its origin as the catalogue other frameworks are cross-referenced against.
Control
Privileged access is reviewed each quarter by the system owner
PPTDF applicability
One owner · one procedure · one evidence trail
20
Control families
0 to 5
Maturity scored
Graded
Mapping to other standards
PPTDF
Applicability on every control
Control families
The full catalogue lives in the library with enhancements as sub-controls. These are the families a GRC team touches most.
Account management, least privilege, separation of duties and session control.
Control assessments, plans of action and milestones, and continuous monitoring.
Baselines, change control and component inventory, which is the asset register.
Handling, reporting and learning, recorded as findings and loss events.
Categorisation, vulnerability monitoring and the assessment itself, fed from the risk register.
Supplier assessment, provenance and notification, which runs on the third-party register.
Platform mapping
Each family imports as a domain with its controls and enhancements beneath, navigable and reportable without flattening the structure.
Where an ISO/IEC 27001 or CSF requirement is satisfied by an 800-53 control, the mapping is recorded with its grade. One test, every framework that asks.
A POA&M item is a finding with an owner, activities, dependencies and reviewed evidence, not a separate tracker.
Scheduled control tests and indicators with thresholds are how the monitoring family is evidenced without a manual quarterly sweep.
Scope which controls apply to which entity, so a low-impact subsidiary is not assessed against a high-impact baseline.
People, Process, Technology, Data and Facility tags let a remediation programme be scoped by what kind of control it is.
Maturity
Every control in the catalogue is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.
Level 0
Not Performed
The practice does not happen. Recorded as an explicit level rather than a blank.
Level 1
Performed Informally
It happens, but it depends on individuals and is neither planned nor tracked.
Level 2
Planned & Tracked
Planned, resourced, and monitored, though practice still varies between teams.
Level 3
Well Defined
A defined standard process, applied consistently across the organisation.
Level 4
Quantitatively Controlled
Measured against targets, with deviation detected from the measurements themselves.
Level 5
Continuously Improving
Improvement is fed by the measurements, changing the process rather than the reporting.
Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.
No commitment required. A typical demo runs 45 minutes.