Privileged Access Register
Purpose
Use this register to record and review accounts with administrator, elevated, or otherwise high-risk access.
Privileged accounts can make major changes to systems, security settings, data, backups, identities, or business processes. They should therefore receive stronger protection and more frequent review than ordinary user accounts.
Register Fields
Use one row for each privileged account.
Account Details
Account name:
Named user or service:
Account owner:
Department or vendor:
Account type:
- Individual admin
- Shared admin
- Service account
- Emergency / break-glass
- Vendor / MSP
- Application administrator
- Other: ____________________
System or Service
System or service:
Business owner:
Technical owner:
Privilege Level
Privilege or role:
Examples:
- Global Administrator
- Domain Administrator
- Server Administrator
- Backup Administrator
- Security Administrator
- Finance Administrator
- Application Administrator
- Database Administrator
- Root
- Cloud Administrator
Business Justification
Why is privileged access required?
Security Controls
MFA enabled:
- Yes / No / Not Supported
Separate admin account:
- Yes / No / Not Applicable
Password or secret stored securely:
- Yes / No
Approved device restriction:
- Yes / No / Not Applicable
Remote access restricted:
- Yes / No / Not Applicable
Admin activity logged:
- Yes / No / Unknown
Shared credential:
- Yes / No
Access Status
- Active
- Temporary
- Disabled
- Under review
- Pending removal
Temporary Access
Temporary access:
- Yes / No
Start date:
Expiry date:
Approval
Approved by:
Approval date:
Review
Last reviewed:
Reviewed by:
Still required:
- Yes / No
Permissions appropriate:
- Yes / No
MFA confirmed:
- Yes / No
Unused or unnecessary privileges found:
- Yes / No
Next review date:
Removal
Removal required:
- Yes / No
Removal owner:
Removal due date:
Removal completed:
Evidence location:
Notes
Recommended Review Frequency
Critical administrator accounts:
- Quarterly or more frequently.
Other privileged accounts:
- At least every six months.
Vendor and MSP privileged accounts:
- Review when engagements change and at least quarterly where practical.
Emergency accounts:
- Review after every use and periodically confirm they remain protected and functional.
What Good Looks Like
The company should be able to identify:
- Every important privileged account.
- Who owns it.
- Why it exists.
- Where it can be used.
- Whether MFA is enabled.
- Whether its activity is logged.
- When it was last reviewed.
- Whether it is still needed.
Practical Rule
Privileged access should be rare, named, protected, visible, and regularly reviewed.