N.4.02 Special access rights
Control Overview
This control mandates that the organization strictly regulates the lifecycle of privileged accounts, such as system, network, and application administrators. Because highly privileged access presents a high-value target for attackers, the organization must establish rigorous procedures for granting, modifying, and revoking these rights. A chronological ledger (audit trail) must be maintained to show exactly who holds elevated privileges and the precise dates when those permissions were modified or withdrawn. Additionally, privileged access must be heavily monitored, bound by strict authentication policies, and reviewed regularly.
Applicability Note: This control is highly critical and fully applicable to the anDREa platform, as it directly governs root, global, and subscription-level administrative capabilities across our technical environments.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, moving away from standing administrative privileges toward a dynamic, zero-standing-access architectural model.
Rather than granting permanent, high-privilege access to technical staff, anDREa utilizes Azure Privileged Identity Management (PIM) to enforce Just-In-Time (JIT) elevation. By default, engineers operate with standard user permissions. When an administrative task is required, personnel must explicitly request temporary elevation via PIM. This elevation demands mandatory Multi-Factor Authentication (MFA) step-up verification, logs a formal business justification, and automatically expires after a predefined period. The definitive list of who can request these roles is maintained in the anDREa People directory, and the operational usage of these privileges is subjected to strict oversight.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.08.02 - Privileged access rights | Mandates that the allocation and use of privileged access rights are restricted and traceably controlled. |
| ISO/IEC 27001 | A.05.15 - Access control, *A.05.16 - Identity management | Controls the foundational access parameters and identity structures that feed into privileged ecosystems. |
| ISO/IEC 27001 | A.05.17 - Authentication information | Governs the secure handling, reset workflows, and multi-factor requirements for high-privilege identities. |
| Technical Infrastructure | Azure PIM Configuration Baselines | Technical system policies proving JIT execution, forced timeout parameters, and mandatory justification logging. (Azure PIM Review) |
| Access Registry | anDREa People HR | The central directory listing the precise mapping of identities authorized to activate specific administrative profiles. |
| Governance Oversight | Information Security Management Board (ISMB) Meetings | Clear audit records proving that monthly PIM activation reviews are compiled, trend-analyzed, and minuted by the Information Security Management Board. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Just-in-time technical boundaries, mandatory MFA step-ups, unalterable activation logging, and monthly management review loops are fully operationalized and verified.