Orphaned Account Checker

Service account

A named person in the team that runs the application owns it, knows what it can reach and answers the review; a department or a mailbox is not a person.

Who should own a service account, and which ISO/IEC 27001, SOC 2 and PCI DSS clauses apply?

The clauses the checker cites on a service account: ISO/IEC 27001 A.5.15, ISO/IEC 27001 A.5.16, ISO/IEC 27001 A.8.2, SOC 2 CC6.1, PCI DSS 7.2.5, PCI DSS 7.2.5.1, PCI DSS 8.6.1 and PCI DSS 8.6.3. Every clause it cites, across the seven regimes, is in the table below.

How the checker reads it

Findings that can apply

9 of 14

Clauses

11 cited
RegimeClause
ISO/IEC 27001ISO/IEC 27001 A.5.15 Access control
ISO/IEC 27001ISO/IEC 27001 A.5.16 Identity management
ISO/IEC 27001ISO/IEC 27001 A.8.2 Privileged access rights
SOC 2SOC 2 CC6.1 Logical access security over protected information assets
PCI DSSPCI DSS 7.2.5 Application and system accounts least privilege
PCI DSSPCI DSS 7.2.5.1 Application and system account access reviewed periodically
PCI DSSPCI DSS 8.6.1 Interactive use of system accounts controlled
PCI DSSPCI DSS 8.6.3 System account passwords protected against misuse
NIST SP 800-53NIST SP 800-53 IA-9 Service Identification and Authentication
NIST SP 800-53NIST SP 800-53 AC-2 Account Management
CIS ControlsCIS Controls 5.5 Establish and Maintain an Inventory of Service Accounts

The first clause, set out

ISO/IEC 27001 A.5.15Access control

Rules that govern both physical entry and logical access to information and associated assets are to be set and applied on the basis of business and information security requirements. Purpose (stated in ISO/IEC 27002:2022): ensures access to information and associated assets is authorized and unauthorized access is prevented. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.15.

What an auditor asks to see: Statement of Applicability entry for control A.5.15, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements; Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification; Evidence of a default-deny design in firewall rules, application roles and cloud IAM policies; Separation of request, approval and administration functions in the access management workflow
Where account lists usually fall short: The access control policy exists but is not reflected in actual system configurations; Default-allow rules persist in network or cloud environments; Non-human entities such as service accounts are left outside the access rules; Access rights are not aligned with classification, so sensitive data is broadly accessible
Source: ISO/IEC 27001:2022 Annex A

A line that reads as this type

the type column left blank, invented values

svc-print-queue | | directory | | yes

See the specimen run