## Purpose

Use this register to record and review accounts with administrator, elevated, or otherwise high-risk access.

Privileged accounts can make major changes to systems, security settings, data, backups, identities, or business processes. They should therefore receive stronger protection and more frequent review than ordinary user accounts.

## Register Fields

Use one row for each privileged account.

### Account Details

Account name:

---

Named user or service:

---

Account owner:

---

Department or vendor:

---

**Account type:**

- Individual admin
- Shared admin
- Service account
- Emergency / break-glass
- Vendor / MSP
- Application administrator
- Other: ____________________

### System or Service

System or service:

---

Business owner:

---

Technical owner:

---

### Privilege Level

Privilege or role:

---

**Examples:**

- Global Administrator
- Domain Administrator
- Server Administrator
- Backup Administrator
- Security Administrator
- Finance Administrator
- Application Administrator
- Database Administrator
- Root
- Cloud Administrator

### Business Justification

Why is privileged access required?

---

### Security Controls

**MFA enabled:**

- Yes / No / Not Supported

**Separate admin account:**

- Yes / No / Not Applicable

**Password or secret stored securely:**

- Yes / No

**Approved device restriction:**

- Yes / No / Not Applicable

**Remote access restricted:**

- Yes / No / Not Applicable

**Admin activity logged:**

- Yes / No / Unknown

**Shared credential:**

- Yes / No

### Access Status

- Active
- Temporary
- Disabled
- Under review
- Pending removal

### Temporary Access

**Temporary access:**

- Yes / No

Start date:

---

Expiry date:

---

### Approval

Approved by:

---

Approval date:

---

### Review

Last reviewed:

---

Reviewed by:

---

**Still required:**

- Yes / No

**Permissions appropriate:**

- Yes / No

**MFA confirmed:**

- Yes / No

**Unused or unnecessary privileges found:**

- Yes / No

**Next review date:**

---

### Removal

**Removal required:**

- Yes / No

Removal owner:

---

Removal due date:

---

Removal completed:

---

Evidence location:

---

### Notes

---

## Recommended Review Frequency

**Critical administrator accounts:**

- Quarterly or more frequently.

**Other privileged accounts:**

- At least every six months.

**Vendor and MSP privileged accounts:**

- Review when engagements change and at least quarterly where practical.

**Emergency accounts:**

- Review after every use and periodically confirm they remain protected and functional.

## What Good Looks Like

The company should be able to identify:

- Every important privileged account.
- Who owns it.
- Why it exists.
- Where it can be used.
- Whether MFA is enabled.
- Whether its activity is logged.
- When it was last reviewed.
- Whether it is still needed.

## Practical Rule

Privileged access should be rare, named, protected, visible, and regularly reviewed.
