NIST SP 800-53 Rev. 5 · Access Control
AC-6(7) — Review of User Privileges
Privileged role without documented ownership. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.
Why this matters
Powerful access that nobody in the organization owns or has reviewed
Someone grants a colleague elevated access to solve an urgent problem. Years later the access is still there, the colleague has changed roles twice, and nobody can say who approved it or why. Organizations are expected to review privileged access periodically, but a review needs a list of who is accountable for each grant, and that list is usually the thing that was never written down.
Why this check earns its place. It reports the absence of a record rather than a technical fault. That is a different kind of finding, and it is the one that makes the periodic review possible at all.
- What it reads
- The organization's own register of administrative roles and who is accountable for each.
- What it reports
- Administrative roles with no named owner, no recorded reason for existing, or a review that is overdue.
See related public disclosures on the Signals page →
The requirement
The organization must review the privileges assigned to users at an organization-defined frequency to validate the need for such privileges, and reassign or remove privileges when no longer appropriate.
NIST SP 800-53 Rev. 5 — AC-6(7) (Least Privilege | Review of User Privileges).
NIST requires periodic validation of privilege need. Whether that is evidenced by an owner field, a ticket reference, or a signed attestation is an organization-defined implementation choice. A missing field is evidence about the record, not proof about the access.
What a check finds
Privileged role lacking a documented owner or justification, or overdue for its required review.
Choose your platform
CISA performance goals
- 3.H — Implement the principles of least privilege
- 3.G — Administrators maintain separate user and privileged accounts (partial)
What a result does not prove
A missing field is evidence about the completeness of the register, not proof that the access itself is inappropriate. Documentation may exist outside the queried source.