Restrict administrative privileges
Administrative (admin) accounts can install software and change security settings, which is exactly why attackers hunt for them first. This control keeps admin rights to the few people who need them, keeps admin accounts separate from everyday ones, and makes sure privileged access is reviewed and logged.
It is control 5 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
One stolen admin account can undo every other defence you have. That is why questions about separating and reviewing admin accounts turn up on most cyber-insurance questionnaires.
Maturity Level 1: the baseline
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Is a request checked and approved before anyone is given admin access to your systems?
ACSC requirement: “Requests for privileged access to systems, applications and data repositories are validated when first requested.”
Do people with admin rights use a separate admin account for admin work, and a normal account for everyday work?
ACSC requirement: “Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.”
Are admin accounts blocked from browsing the web and reading email (unless explicitly authorised)?
ACSC requirement: “Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.”
Maturity Level 2: the common target
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Is admin access automatically disabled if it hasn't been used for 45 days?
ACSC requirement: “Privileged access to systems and applications is disabled after 45 days of inactivity.”
Are passwords for built-in admin, service and emergency accounts long, unique, unpredictable and stored securely?
ACSC requirement: “Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.”
Is admin activity (privileged sign-ins and actions) recorded in a central log?
ACSC requirement: “Privileged access events are centrally logged.”
Maturity Level 3: advanced
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Is admin access granted only temporarily when needed ('just-in-time'), rather than standing all the time?
ACSC requirement: “Just-in-time administration is used for administering systems and applications.”
These are the criteria our free self-assessment checks. They are a representative subset of the full ACSC model, which has more requirements at each level. You can read the full model at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).