risk
Excessive privilege and wrong assignment of access rights
Overly broad or wrongly assigned access rights, applications/services running with excessive privileges, and failure to enforce least privilege — a compromise or insider then gains broad access to systems and data.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Access Control & Identity Management
- Data Protection & Privacy
- taxonomy
- iso-27005-vulnerability
- nist-800-30-threat-event
- nist-privacy-risk
- inherent_rating
- high
Details
- risk_id
- access-excess-privilege
- category
- cyber_security
- likelihood
- high
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
- nist-800-30-threat-event
- nist-privacy-risk
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-02 — Review user access rights periodically mitigates Excessive privilege and wrong assignment of access rights
- strength
- primary
- rationale
- Reviews confirm each entitlement stays business-limited and remove excess privilege, directly catching privilege creep and wrong assignment.
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software mitigates Excessive privilege and wrong assignment of access rights
- strength
- primary
- rationale
- Individually justified, time-bound privileged rights on separate admin accounts directly curb excessive privilege.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Excessive privilege and wrong assignment of access rights
- strength
- primary
- rationale
- Roles defaulting to least privilege on need-to-know are the direct defense against overly broad or wrongly assigned access rights.
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle mitigates Excessive privilege and wrong assignment of access rights
- strength
- related
- rationale
- Role-based, owner-approved provisioning and modify-on-role-change help limit wrong assignment and accumulation, but the operative least-privilege defense is role design (UC-03) and periodic access review (UC-02).