# AC-2(7) — Privileged User Accounts

- **Control ID:** AC-2(7)
- **Family:** [AC](/md/families/AC.md)
- **Baselines:** No content available.
- **Enhancement of:** [AC-2](/md/controls/AC-2.md)

## Description

Establish and administer privileged user accounts in accordance with \[assignment\]; Monitor privileged role or attribute assignments; Monitor changes to roles or attributes; and Revoke access when privileged role or attribute assignments are no longer appropriate.

## Discussion

Privileged roles are organization-defined roles assigned to individuals that allow those individuals to perform certain security-relevant functions that ordinary users are not authorized to perform. Privileged roles include key management, account management, database administration, system and network administration, and web administration. A role-based access scheme organizes permitted system access and privileges into roles. In contrast, an attribute-based access scheme specifies allowed system access and privileges based on attributes.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

No content available.

## Related controls

No content available.

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
