Why: Individual least-privilege access on OT platforms, engineering functions held to authorized staff, and standing vendor accounts driven to zero are the principle of least privilege enacted on production systems.
What this does not claim: Holds only for OT systems inside the CUI boundary. The requirement's weight in most assessments falls on the IT estate — privileged account separation, security function restriction, admin group review — none of which this OT-focused practice performs; those need their own implementation and evidence.
- Grant individuals the minimum OT access their role requires, where platforms support distinct roles
- Provision vendor access per engagement and revoke it afterward rather than leaving standing accounts
- Review who holds engineering-level access on a cadence
- OT access reviews showing removals and role reductions
- Vendor account provisioning and revocation records per engagement
Where this holds: Holds only for OT systems within the organization's CUI boundary.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06