IR-04.3: Full administrative access may be needed in significant incidents to take immediate actions, such as securing exposed customer data.
This access should require a "break glass" process with dual-authority approval, MFA and full auditability. Any use of full admin access to a production deployment should be considered a critical incident that requires secondary review.
Control automation: Either
AWS control specification: * A full-admin IAM role exists in the account
That role is designated for incident responders (can check automatically by using a consistent role name that is the basis for the automated check)
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: Pass if the CSPM/CNAPP includes JIT or other CIEM capabilities assigned to the incident response team
Description
Control automation: Either
AWS control specification: * A full-admin IAM role exists in the account
That role is designated for incident responders (can check automatically by using a consistent role name that is the basis for the automated check)
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: Pass if the CSPM/CNAPP includes JIT or other CIEM capabilities assigned to the incident response team