Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.01.06OFFICIAL TITLEPENDING NIST SME REVIEW

03.01.06Least Privilege — Privileged Accounts

03.01 Access Control · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires restricting privileged accounts on the system to organization-defined personnel or roles, and requiring that users with privileged accounts use non-privileged accounts when accessing nonsecurity functions or nonsecurity information (aligned to SP 800-53 AC-6(2) and AC-6(5)).

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Admin rights belong to named people in named roles, and those people carry two identities: a daily account for email and browsing, and a separate privileged account used only for admin work. The point is blast radius — a phished daily account that is also a domain admin is a company-ending event; the same phish against a mail-only account is a bad afternoon.

Across revisions

Rev. 3 pairs Rev. 2's use-non-privileged-accounts rule (3.1.6) with an explicit restriction of privileged accounts to organization-defined personnel or roles.

Mapped practices

Brilliant at the Basics practices that support this requirement

Partial implementation supportModerate confidence

Why: Keeping controller configuration and safety-system access behind a small set of named privileged identities is this requirement's restriction of privileged accounts, applied where its failure hurts most.

What this does not claim: The requirement's second half — privileged users switching to non-privileged accounts for nonsecurity work — collides with the shared consoles and always-logged-on HMIs common in plants; where the pattern cannot hold, the deviation needs a documented compensating measure such as dedicated engineering workstations. Privileged accounts on the IT estate are separate work the practice does not reach.

Practice-side activities
  • Restrict controller and safety-system administration to named roles on dedicated engineering workstations
  • Keep browsing and email off engineering workstations so privileged sessions stay single-purpose
Evidence this produces
  • Privileged OT role membership lists
  • Engineering-workstation configuration showing restricted use

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Issue separate admin accounts to each administrator and strip admin rights from daily accounts — including the owner's.
  • Keep privileged-role membership short, named, and reviewed; 'temporary' members are the entropy source.
  • Keep email, browsing, and productivity licenses off admin accounts so the separation is enforced rather than aspirational.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Privileged-role membership lists mapped to named personnel and roles
  • Directory evidence of separate admin and daily accounts for each administrator
  • Configuration showing admin accounts excluded from mail and collaboration services

Suggested owners, derived from the mapped practices and artifacts: Plant / OT leader · Identity admin. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated