Privileged User
PCIComplianceHubLast updated
Any user account with more than basic access: administrator accounts most obviously, but also accounts that can approve, export, configure or delete beyond what a standard user can. How much more varies by organisation, role and technology, which is why the standard asks for the privileges to be justified rather than for a fixed list.
Applies to. Every in-scope system. 7.2.2 requires privileges to be assigned by job classification and function and to be the least needed to perform it.
Example. A finance user who can run refunds is privileged relative to one who can only view orders. 7.2.2 asks why that user needs refunds; 7.2.4 asks, at least every six months, whether they still do; 10.2.1.2 logs everything an administrative user does.
Limits. Privilege is relative to the system, not to the org chart: a junior engineer with root is a privileged user and a director with read-only access is not. The controls that follow from it are the access review (7.2.4), MFA for administrative access into the CDE (8.4.1), and the logging of administrative actions (10.2.1.2). The Council's separate term for the highest tier is administrative access.