Establish and enforce a policy that prohibits administrative accounts from using
applications that access the Internet, such as web browsers, or with potential
Internet sources, such as email. Define specific exceptions for local service
administration. These exceptions may include HTTP(S)-based tools that are used for
the administration of the local system, services, or attached devices.
Implement technical measures where feasible such as removal of applications or
use of application whitelisting to restrict the use of applications that can access the
Internet.
Determine whether administrative accounts are prevented from using applications
that access the Internet, such as web browsers, or with potential Internet sources,
such as email, except as necessary for local service administration.
The organization must have a policy that prohibits administrative accounts from
using applications that access the Internet, such as web browsers, or with potential
Internet sources, such as email, except as necessary for local service
administration. The policy should define specific exceptions for local service
administration. These exceptions may include HTTP(S)-based tools that are used
for the administration of the local system, services, or attached devices.