Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.4.02 Special access rights

Control Overview

This control mandates that the organization strictly regulates the lifecycle of privileged accounts, such as system, network, and application administrators. Because highly privileged access presents a high-value target for attackers, the organization must establish rigorous procedures for granting, modifying, and revoking these rights. A chronological ledger (audit trail) must be maintained to show exactly who holds elevated privileges and the precise dates when those permissions were modified or withdrawn. Additionally, privileged access must be heavily monitored, bound by strict authentication policies, and reviewed regularly.

note

Applicability Note: This control is highly critical and fully applicable to the anDREa platform, as it directly governs root, global, and subscription-level administrative capabilities across our technical environments.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, moving away from standing administrative privileges toward a dynamic, zero-standing-access architectural model.

Rather than granting permanent, high-privilege access to technical staff, anDREa utilizes Azure Privileged Identity Management (PIM) to enforce Just-In-Time (JIT) elevation. By default, engineers operate with standard user permissions. When an administrative task is required, personnel must explicitly request temporary elevation via PIM. This elevation demands mandatory Multi-Factor Authentication (MFA) step-up verification, logs a formal business justification, and automatically expires after a predefined period. The definitive list of who can request these roles is maintained in the anDREa People directory, and the operational usage of these privileges is subjected to strict oversight.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.02 - Privileged access rightsMandates that the allocation and use of privileged access rights are restricted and traceably controlled.
ISO/IEC 27001A.05.15 - Access control, *A.05.16 - Identity managementControls the foundational access parameters and identity structures that feed into privileged ecosystems.
ISO/IEC 27001A.05.17 - Authentication informationGoverns the secure handling, reset workflows, and multi-factor requirements for high-privilege identities.
Technical InfrastructureAzure PIM Configuration BaselinesTechnical system policies proving JIT execution, forced timeout parameters, and mandatory justification logging. (Azure PIM Review)
Access RegistryanDREa People HRThe central directory listing the precise mapping of identities authorized to activate specific administrative profiles.
Governance OversightInformation Security Management Board (ISMB) MeetingsClear audit records proving that monthly PIM activation reviews are compiled, trend-analyzed, and minuted by the Information Security Management Board.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Just-in-time technical boundaries, mandatory MFA step-ups, unalterable activation logging, and monthly management review loops are fully operationalized and verified.