Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

98 controls

03.14.09Dedicated administration workstationITSP.10.171System and information integrity

Official Requirement

A. Require any administrative or superuser actions to be performed from a physical workstation which is dedicated to those specific tasks and isolated from all other functions and networks, and especially from any form of internet access. B. Remote connection of a DAW to a target network is to use carrier private networks (e.g., virtual private LAN service (VPLS) or multiprotocol label switching (MPLS)) with VPN encryption. C. Use a dedicated and hardened single-purpose physical workstation or thin client as the DAW, that is not shared between security realms.

Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3

In Plain English

All administrative and superuser tasks must be performed from a dedicated administration workstation (DAW) that is physically isolated from general-purpose networks and has no direct Internet access. Remote DAW connections must use private networks with VPN encryption. The DAW must be a hardened, single-purpose device not shared across different security environments.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Dedicated administration workstation deployment

Implementation steps

  1. Provision dedicated physical workstations for all administrative tasks, isolated on a separate management VLAN with no Internet access
  2. Harden DAWs using CIS Benchmarks or DISA STIGs; remove all non-essential software, browsers, and email clients
  3. Implement carrier private network or MPLS with VPN encryption for any remote DAW connectivity requirements
  4. Enforce that DAWs are not shared between security realms and are used exclusively for administrative purposes

Tools / systems

Evidence artifacts

Evidence frequency: Continuous enforcement; quarterly DAW configuration audit; annual architecture review