FillTrust

How to answer

Is access granted on a least-privilege basis?

The honest small-company answer is rarely a clean yes, and the answer that names its exceptions is stronger than the one that does not.

A model answerImplied, not stated

Yes. Access is granted by role rather than individually, production access is limited to [the engineers] who need it for their duties, and requests are approved by an owner before being granted. Administrative access is separate from day-to-day access.

Square brackets are yours to fill in. FillTrust grades an answer like this implied, not stated when your documents support it.

Answered from
Your access control policy, and the access section of your SOC 2 report.
Evidence to attach
Occasionally a role matrix, or a screenshot of the roles configured in your cloud account.
Where it is asked
CAIQ v4.0 · IAM-05SIG LiteISO 27001 Annex A · A.5.15

Least privilege is a principle, so the question is really asking for evidence that somebody thought about who needs what, rather than granting everything to everyone because it was faster.

Say how access is granted, not that it is minimal. "Access is granted by role, requested from an owner, and reviewed quarterly" describes a mechanism. "Access follows the principle of least privilege" describes an intention, and reviewers have read that sentence several thousand times.

Separate the two kinds of access. There is the access an engineer needs to do their job, and there is administrative access that can change the configuration itself. Keeping those apart, even informally, is the single most convincing detail available here: a small team where two people hold cloud administrator rights and everyone else has scoped roles is a good answer, and it is one most teams can give truthfully.

Shared credentials are the thing to fix first. If a root account, a database user or a vendor portal login is shared between people, least privilege is not in place regardless of what the policy says, and it also breaks your audit trail, your offboarding answer and your access review answer at the same time. It is worth solving before answering, because it is the single dependency underneath four separate questions.

Production data access deserves its own sentence. Reviewers care much more about who can read the customer database than about who can deploy. If access to production data requires a separate elevation, is logged, and is limited to a named few, say that explicitly rather than folding it into a general statement.

Where this lands. Usually implied. Most policies assert the principle and few documents show the roles. If you write down the three or four roles you actually use and who holds the administrative one, this becomes a confirmed answer, and the access review question next to it becomes much easier to answer as well.

How this one goes wrong

Specific to this question, not general advice.

  • Answering yes when everybody is an administrator. It is a common and survivable state at ten people, and claiming otherwise is what turns it into a finding.
  • Describing roles that exist in a document but not in the cloud account. The reviewer's follow-up is a screenshot of who currently holds the admin role.
  • Forgetting that shared accounts defeat this entirely. One set of credentials three people use is the clearest possible failure of least privilege.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.