Administrative Access

PCIComplianceHubLast updated

Elevated privileges that let an account manage a system, network or application rather than merely use it: root, administrator, superuser, sysadmin and their equivalents, whether held by a person's own account or by a built-in system account.

Applies to. Every account that can change a system component's configuration, security settings or software, on every in-scope system.
Example. A database administrator's account, the local administrator on a point-of-sale server, and the root account on a firewall are all administrative access. Each must be encrypted in transit when used over a network (2.2.7), authenticated with MFA (8.4.1), and logged action by action (10.2.1.2).
Limits. Administrative access is not defined by the account's name but by what it can do: an account called 'reports' that can alter the database schema is administrative. The standard does not forbid it; it requires it to be justified by role (7.2.1), granted to the fewest people (7.2.6), and attributable to an individual even when a shared system account is used, which is what 10.2.1.2's logging of interactive use of system accounts is for.
In PCI DSS v4.0.1. 2.2.7, 7.2.1, 7.2.6, 8.4.1, 10.2.1.2