IR-04.3: Full administrative access may be needed in significant incidents to take immediate actions, such as securing exposed customer data. This access should require a "break glass" process with dual-authority approval, MFA and full auditability. Any use of full admin access to a production deployment should be considered a critical incident that requires secondary review.
  • Control automation: Either
  • AWS control specification: * A full-admin IAM role exists in the account
  • That role is designated for incident responders (can check automatically by using a consistent role name that is the basis for the automated check)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: Pass if the CSPM/CNAPP includes JIT or other CIEM capabilities assigned to the incident response team

Description

  • Control automation: Either
  • AWS control specification: * A full-admin IAM role exists in the account
  • That role is designated for incident responders (can check automatically by using a consistent role name that is the basis for the automated check)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: Pass if the CSPM/CNAPP includes JIT or other CIEM capabilities assigned to the incident response team