Domain 5: Protection of Information Assets7 min · 3 questions

Privileged Access Management

Administrator accounts can switch off the controls that protect everything else, which is why they get the tightest handling. The exam tests why privileged access is the priority and how it is controlled.

What this makes you able to do

Evaluate whether privileged accounts are minimised, tightly controlled, and their use monitored.

By the end you can

  • Explain why privileged accounts carry the greatest risk.
  • Identify the controls that manage privileged access.
  • Recognise the risk of using privileged accounts for everyday work.

Transcript

Privileged access management. The previous lessons controlled ordinary access. Privileged access is a category of its own, because it can undo everything else.

The scene. Every administrator shares one domain-admin account, they use it all day for email and browsing as well as administration, and no one reviews what it does. The reasoning is that admins are trusted senior staff and the password is strong. Then one of them clicks a phishing link while logged in as domain admin, and the attacker inherits control of the entire environment in a single step.

Why are privileged accounts the priority. Because a privileged account, an administrator, domain admin, root, or database administrator, can do what ordinary accounts cannot: change configurations, disable logging, grant itself more access, and reach almost any data. A compromised one can dismantle the whole control environment.

And the consequence is asymmetric. A compromised standard account is a contained problem; a compromised privileged account can turn off the very monitoring that would catch it, and reach everything. Attackers know this, so privileged credentials are what they hunt for first. When a question asks why administrator accounts warrant the tightest control, it is their capability, not their password or their frequency of use.

Because the power is extreme, the control is correspondingly tight. First, minimise: the number of privileged accounts and the scope of each.

Second, elevate just in time: grant privileged access only when needed, for as long as needed, rather than as a standing right.

And third, no shared admin accounts, so privileged actions are attributable; M-F-A on privileged access, always; and record and review the sessions, exactly the discipline applied to the D-B-A in Domain four.

A strong password alone does none of this. The power of the access is matched by minimising it, elevating it only when required, and watching how it is used. That is what privileged access management means.

Which brings us to the phishing click, the scenario the exam loves. Everyday email and web browsing are where phishing and malware land, so performing them under a privileged account means a routine compromise becomes a full-environment compromise in one move.

So the fix is that administrators hold a separate standard account for daily work and use the privileged account only for administrative tasks, so the powerful credential is exposed as little as possible. You do not live in the privileged account.

And for genuine emergencies, a controlled break-glass procedure grants access when truly needed, and it is reviewed afterwards. Powerful access stays accountable even when it is urgent.

So carry this away. Privileged accounts warrant the tightest control because their compromise is catastrophic: minimise them, elevate just in time, never share, use M-F-A, and monitor the sessions. And daily work belongs in a standard account; the privileged one is used only when the task genuinely requires it, so a single phishing click cannot hand over the whole environment.

Knowledge check
0 / 3
  1. 1.Why are privileged (administrator) accounts the HIGHEST priority to control?

  2. 2.Which of the following BEST controls privileged access?

  3. 3.An administrator uses their privileged domain-admin account for everyday email and web browsing. What is the MAIN concern?

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.