Orphaned Account Checker

Break-glass or emergency account

A named person answers for it and a second person checks each use; it is expected to sit unused between emergencies, so it is never read as dormant.

Who should own a break-glass or emergency account, and which ISO/IEC 27001, SOC 2 and PCI DSS clauses apply?

The clauses the checker cites on a break-glass or emergency account: ISO/IEC 27001 A.8.2, ISO/IEC 27001 A.5.16 and PCI DSS 8.2.2. Every clause it cites, across the seven regimes, is in the table below.

How the checker reads it

Findings that can apply

7 of 14

Clauses

6 cited
RegimeClause
ISO/IEC 27001ISO/IEC 27001 A.8.2 Privileged access rights
ISO/IEC 27001ISO/IEC 27001 A.5.16 Identity management
PCI DSSPCI DSS 8.2.2 Shared and generic IDs only by exception
NIST SP 800-53NIST SP 800-53 AC-2 Account Management
CIS ControlsCIS Controls 6.5 Require MFA for Administrative Access
NIS2NIS2 Art. 21(2)(j) Multi-factor or continuous authentication, secured communications and secured emergency communications

The first clause, set out

ISO/IEC 27001 A.8.2Privileged access rights

The granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2.

What an auditor asks to see: Statement of Applicability entry for control A.8.2, showing inclusion or justified exclusion, implementation status and the risks it treats; An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry; Privileged access management configuration showing time-limited elevation, step-up authentication and session recording; Privileged access review records performed periodically and after organizational changes
Where account lists usually fall short: Administrators use their privileged account for email and web browsing; Shared generic administrator accounts are used with no individual accountability; Privileged rights are standing and never expire; Service accounts with administrative rights are excluded from reviews
Source: ISO/IEC 27001:2022 Annex A

A line that reads as this type

the type column left blank, invented values

breakglass-01 | | directory | | yes

See the specimen run