A.8.18 Use of Privileged Utility Programs
Control Objective
The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled.
Policy Statement
anDREa strictly controls and restricts the installation and execution of privileged utility programs—including diagnostic software, system overrides, and low-level debugging packages—capable of bypassing standard application rules or security profiles. Unauthorized deployment of these utilities introduces substantial risk and is technically mitigated across all layers of our software stack.
Privilege Control Framework
The inventory, execution limits, and tracking metrics for highly privileged programs are cataloged into three explicit deployment environments:
- Corporate Workstations: Endpoint devices are locked down via central Mobile Device Management (MDM). Local user accounts lack administrative rights, blocking the execution of unauthorized partition managers, registry overrides, or local packet-sniffing utilities.
- myDRE as a SaaS Platform: Cloud orchestration engines, multi-tenant routers, and underlying platform controllers are restricted using native Role-Based Access Control (RBAC). Only authenticated engineering personnel operating under Just-In-Time (JIT) elevation pathways can run administrative maintenance scripts (see A.08.03 - Information access restriction).
- Research Virtual Machines (VMs): While virtual assets are under the shared custody of the customer, platform-level resource managers that interface with the virtualization fabric are tightly ring-fenced to prevent unauthorized VM snapshotting or cross-workspace memory manipulation.
Compliance and Operational Governance
Any deployment or use of a privileged utility program must align strictly with the formalized rules established, which mandates:
- Explicit Authorization: Prior approval from the Asset Owner before any diagnostic or override utility can be run.
- Permitted Tools Only: Adherence to a pre-vetted index of acceptable maintenance packages.
- Continuous Auditing: All inputs, administrative flags, and technical overrides executed via these programs are permanently stored in immutable logging directories.