PR.AA-05_praa-05
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least
Physical access to assets is managed, monitored, and enforced commensurate with risk
Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes
Physical access to assets is managed and protected
Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties
Network integrity is protected (e.g., network segregation, network segmentation)
Identities are proofed and bound to credentials and asserted in interactions
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in
Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with