NIST 800-171 Controls · Access Control
AC.2.005 — Employ Least Privilege
Employ the principle of least privilege, including for specific security functions and privileged accounts.
What AC.2.005 means in plain English
Give everyone the minimum access they need to do their job — nothing extra. If your machinist only needs to read job traveler files, don't give them write or delete access. If your office manager doesn't need to change system settings, make sure they can't. This limits the damage if an account gets hacked or an employee makes a mistake.
The assessment question
“Does each employee and each system account have only the minimum permissions required to perform their specific duties — meaning no one has unnecessary admin rights, extra folder access, or software installation privileges beyond what their job requires?”
How to implement AC.2.005
- Conduct an access review: list every user account and what they currently have access to, then ask "does this person actually need this access for their job?" Remove anything that isn't necessary.
- Remove all employees from the local Administrators group on their workstations unless they specifically need admin rights to do their job. Go to Computer Management > Local Users and Groups > Administrators.
- For shared network drives, audit folder permissions and apply the "minimum necessary" test: Read-only for those who only need to view files, Read/Write only for those who must edit, and Full Control only for the folder owner or IT admin.
- Create a separate named "admin account" for IT tasks that is different from the daily-use account. The IT admin should log in with a regular account for email and browsing, and only switch to the admin account when performing IT functions.
- Document your least-privilege decisions in an access matrix and review it at least annually or whenever someone changes roles.
Evidence your assessor will ask for
- Access rights matrix showing each user's permissions across all systems
- Screenshot confirming standard users are not in the local Administrators group
- Evidence of access review (signed-off spreadsheet, email confirmation, or audit log)
- Separate admin account policy or procedure documentation
- Folder permission screenshots for CUI storage locations
Does AI prompt monitoring help with this control? Honestly, no.
AC.2.005 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Access Control controls
Limit System Access to Authorized Users
AC.1.002Limit System Access to Authorized Transaction Types
AC.2.003Control CUI Flow per Authorizations
AC.2.004Separate Duties to Reduce Risk
AC.2.006Use Non-Privileged Accounts for Non-Security Functions
AC.2.007Prevent Non-Privileged Users from Executing Privileged Functions
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.