Domain 04Introduced in v1.0

Identity and Permission Containment

L1L2L322 ACRs (22 defined in current release)

Summary#

Session-scoped permissions, multi-tenancy, and least privilege

Risk Rationale#

Linked ACR Controls#

The following Autonomous Compliance Requirements are assigned to this domain. Each ACR defines a specific, testable control with its own evaluation method, classification, and evidence requirements.

ACR-4.01

The system SHALL NOT escalate its own permissions through any mechanism.

The system SHALL NOT escalate its own permissions through any mechanism.

AT+HSAT+HS|Risk weight: 5/10|
L1L2L3
ACR-4.02

The system SHALL NOT assume unauthorized identities or impersonate users, administrators, or externa

The system SHALL NOT assume unauthorized identities or impersonate users, administrators, or external entities.

AT+HSAT+HS|Risk weight: 5/10|
L1L2L3
ACR-4.03

In multi-tenant environments, the system SHALL maintain strict data isolation between tenants.

In multi-tenant environments, the system SHALL maintain strict data isolation between tenants.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-4.04

Cross-tenant data leakage SHALL be prevented in shared infrastructure environments.

Cross-tenant data leakage SHALL be prevented in shared infrastructure environments.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-4.05

Session-scoped permissions SHALL NOT persist beyond their authorized context.

Session-scoped permissions SHALL NOT persist beyond their authorized context.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-4.06

In multi-tenant environments, the system SHALL maintain strict data isolation between tenants.

In multi-tenant environments, the system SHALL maintain strict data isolation between tenants.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-4.07

Permission assertions SHALL be validated against authoritative identity providers at each access dec

Permission assertions SHALL be validated against authoritative identity providers at each access decision point.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-4.08

The system SHALL detect and reject permission grants from unauthorized sources including injected in

The system SHALL detect and reject permission grants from unauthorized sources including injected instructions claiming elevated authority.

AT+HSAT+HS|Risk weight: 5/10|
L1L2L3
ACR-4.09

Identity and access audit logs SHALL be maintained for all permission decisions.

Identity and access audit logs SHALL be maintained for all permission decisions.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-4.10

Credential management controls SHALL prevent credential exposure in logs, outputs, or error messages

Credential management controls SHALL prevent credential exposure in logs, outputs, or error messages.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-4.11

Separation of duties SHALL be enforced where a single autonomous process cannot both authorize and e

Separation of duties SHALL be enforced where a single autonomous process cannot both authorize and execute high-impact actions.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-4.12

The system SHALL enforce role-based access control with documented role definitions.

The system SHALL enforce role-based access control with documented role definitions.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-4.13

Permission changes SHALL require multi-party authorization for high-impact operations.

Permission changes SHALL require multi-party authorization for high-impact operations.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-4.14

The system SHALL detect and alert on permission anomalies including unusual access patterns and priv

The system SHALL detect and alert on permission anomalies including unusual access patterns and privilege usage spikes.

AT+CMAT+CM|Risk weight: 4/10|
L1L2L3
ACR-4.15

Authentication tokens SHALL have defined expiration periods and be non-replayable.

Authentication tokens SHALL have defined expiration periods and be non-replayable.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-4.16

The system SHALL implement identity verification before processing inter-system requests.

The system SHALL implement identity verification before processing inter-system requests.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-4.17

Permission delegation SHALL be limited in scope, duration, and depth to prevent transitive privilege

Permission delegation SHALL be limited in scope, duration, and depth to prevent transitive privilege escalation.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-4.18

The system SHALL maintain a current inventory of all service accounts, API keys, and autonomous iden

The system SHALL maintain a current inventory of all service accounts, API keys, and autonomous identities.

EIEvidence Inspection|Risk weight: 3/10|
L1L2L3
ACR-4.19

Emergency access procedures SHALL be documented and tested, with all emergency access logged and rev

Emergency access procedures SHALL be documented and tested, with all emergency access logged and reviewed.

EI+ATEI+AT|Risk weight: 4/10|
L1L2L3
ACR-4.20

The system SHALL prevent lateral movement between security zones without explicit authorization.

The system SHALL prevent lateral movement between security zones without explicit authorization.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-4.21

Identity federation with external providers SHALL validate trust chains at each authentication event

Identity federation with external providers SHALL validate trust chains at each authentication event.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-4.22

The system SHALL log and alert on all failed authentication and authorization attempts.

The system SHALL log and alert on all failed authentication and authorization attempts.

AT+CMAT+CM|Risk weight: 3/10|
L1L2L3