INTRA/DP/DP005Privileged access management
The separation, brokering, and time-bounding of access that exceeds ordinary entitlement.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| DP005/EUMandatory | European Union | Commission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026 | What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings. | For the digital infrastructure and service providers it reaches, privileged and system administration accounts carry policies of their own, strong identification and authentication among them, and the systems used to administer are kept for administration and separated from everything else. |
| DP005/ITMandatory | Italy | Determinazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026 | The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter. | For a subject in the national NIS register, every account is inventoried and approved by someone inside the organization, those with administrative privileges and those used for remote access included, and accounts are individual to a user unless there is a documented technical reason otherwise. A system administrator’s privileged and unprivileged accounts are to be completely distinct, and to carry different credentials. |
| DP005/ESMandatory | Spain | Real Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026 | The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action. | Development and operation are not to fall to the same person, nor are authorizing a use and controlling it. At the high category the same person may not hold configuration and maintenance together, and auditing or supervision may not be combined with any other function at all. Accounts carrying audit privileges are strictly controlled and personal to their holder, and the system’s security information is reachable only by the authorized administrators. |
| Recommended | Francewhere written | Guide d'hygiène informatiqueAgence nationale de la sécurité des systèmes d'information · read 29 Aug 2026 | Forty two measures at a standard and a reinforced level, among them the joining, leaving, and function change procedures written with the human resources function, and a minimum retention of one year for security critical events. | An exhaustive inventory of the privileged accounts is kept current, and reviewed periodically to make sure access to sensitive items is held, the working directories and the mailboxes of senior managers named among them. The review is also what removes the access left behind by a departure. A simple naming convention for service and administration accounts is wanted, because it makes both the review and the detection of an intrusion easier. |
| Recommended | Germanywhere written | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | An administrative activity should be one that two people have to carry out together. Where multi-factor authentication is used the factors are split between the two of them, and where a password is used it is divided in two and each of them holds a half. This sits at the grade the compendium keeps for a raised protection need. |
| Recommended | Netherlandswhere written | Baseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026 | The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time. | Only authorized personnel reach the system utilities, and only at the moments when reaching them is strictly necessary. Their use is logged, and the log is available for examination for half a year. |
