Orphaned Account Checker

Built-in or vendor default account

The team that runs the system names one person who answers for it; a built-in account nobody uses is switched off or its default password changed.

Who should own a built-in or vendor default account, and which ISO/IEC 27001, SOC 2 and PCI DSS clauses apply?

The clauses the checker cites on a built-in or vendor default account: ISO/IEC 27001 A.5.17, ISO/IEC 27001 A.8.2 and PCI DSS 2.2.2. Every clause it cites, across the seven regimes, is in the table below.

How the checker reads it

Findings that can apply

8 of 14

Clauses

5 cited
RegimeClause
ISO/IEC 27001ISO/IEC 27001 A.5.17 Authentication information
ISO/IEC 27001ISO/IEC 27001 A.8.2 Privileged access rights
PCI DSSPCI DSS 2.2.2 Vendor default accounts managed
NIST SP 800-53NIST SP 800-53 IA-5 Authenticator Management
CIS ControlsCIS Controls 5.1 Establish and Maintain an Inventory of Accounts

The first clause, set out

ISO/IEC 27001 A.5.17Authentication information

A management process is to control how authentication information is allocated and managed, and it includes telling personnel how to handle such information properly. Purpose (stated in ISO/IEC 27002:2022): ensures proper entity authentication and prevents authentication process failures. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.17.

What an auditor asks to see: Statement of Applicability entry for control A.5.17, showing inclusion or justified exclusion, implementation status and the risks it treats; Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use; Password policy and technical configuration showing length, complexity, reuse prevention, breached-password blocking and masked entry; Records of vendor default credentials being changed at installation
Where account lists usually fall short: Initial passwords are sent in clear text email or use a predictable pattern; Default vendor credentials remain on network devices or appliances; Shared account passwords are not changed when someone who knew them leaves; No check against known breached passwords is performed
Source: ISO/IEC 27001:2022 Annex A

A line that reads as this type

the type column left blank, invented values

admin | | directory | | yes

See the specimen run