---
name: framework-financial-services-controls-ac-2.7
title: AC-2 (7) -  Privileged User Accounts
description: 'Establish and administer privileged user accounts in accordance with _[Selection: a role-based access scheme; an attribute-based access scheme]_.'
last-updated: 2025-02-27
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services-controls?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# AC-2 (7) -  Privileged User Accounts
{: #ac-2.7}

## Control requirements
{: #control-requirements}



### AC-2 (7) (a)


Establish and administer privileged user accounts in accordance with _[Selection: a role-based access scheme; an attribute-based access scheme]_.


### AC-2 (7) (b)


Monitor privileged role or attribute assignments.


### AC-2 (7) (c)


Monitor changes to roles or attributes.


### AC-2 (7) (d)


Revoke access when privileged role or attribute assignments are no longer appropriate.












## NIST supplemental guidance
{: #nist-supplemental-guidance}

Privileged roles are organization-defined roles assigned to individuals that allow those individuals to perform certain security-relevant functions that ordinary users are not authorized to perform. Privileged roles include key management, account management, database administration, system and network administration, and web administration. A role-based access scheme organizes permitted system access and privileges into roles. In contrast, an attribute-based access scheme specifies allowed system access and privileges based on attributes.