Orphaned Account Checker

Person (employee)

The person it belongs to; it ends on the day they leave.

Who should own a person (employee), and which ISO/IEC 27001, SOC 2 and PCI DSS clauses apply?

The clauses the checker cites on a person (employee): ISO/IEC 27001 A.5.16, ISO/IEC 27001 A.5.18, SOC 2 CC6.2 and PCI DSS 8.2.1. Every clause it cites, across the seven regimes, is in the table below.

How the checker reads it

Findings that can apply

7 of 14

Clauses

10 cited
RegimeClause
ISO/IEC 27001ISO/IEC 27001 A.5.16 Identity management
ISO/IEC 27001ISO/IEC 27001 A.5.18 Access rights
SOC 2SOC 2 CC6.2 Registering and authorising users before issuing credentials
PCI DSSPCI DSS 8.2.1 Unique ID assigned to every user
NIST SP 800-53NIST SP 800-53 AC-2 Account Management
NIST SP 800-53NIST SP 800-53 PS-4 Personnel Termination
CIS ControlsCIS Controls 5.1 Establish and Maintain an Inventory of Accounts
CIS ControlsCIS Controls 6.1 Establish an Access Granting Process
CIS ControlsCIS Controls 6.2 Establish an Access Revoking Process
NIS2NIS2 Art. 21(2)(i) Human resources security, access control policies and asset management

The first clause, set out

ISO/IEC 27001 A.5.16Identity management

Identities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.16.

What an auditor asks to see: Statement of Applicability entry for control A.5.16, showing inclusion or justified exclusion, implementation status and the risks it treats; Identity management procedure covering creation, verification, activation, change, disablement and removal; Evidence that identities are verified against trusted documents before issue; A register of shared identities with the business justification and approval for each; A register of non-human identities (service accounts, machine identities) with segregated approval and an independent oversight record
Where account lists usually fall short: Generic shared accounts exist without documented justification or approval; Service accounts have no owner and no periodic oversight; Identities of leavers remain enabled for weeks because HR notifications are not integrated; The same person holds several identities in one directory, undermining accountability
Source: ISO/IEC 27001:2022 Annex A

A line that reads as this type

the type column left blank, invented values

e1042 | | directory | | yes

See the specimen run