11. AI agent credential with no owner or no review
An AI agent reaches data and starts work through its credential; an agent credential with no owner, or one nobody has reviewed, acts outside anyone's account of who can do what.
The rule it applies
An AI agent credential with no owner, a team for an owner, an owner who has left, no review recorded, or a review older than the interval. Without a review column, the review half is a question.
A question for the account owner
Which person owns this agent's credential, and what can it reach?
Clauses
5 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| ISO/IEC 27001 | ISO/IEC 27001 A.5.16 Identity management | every account type |
| ISO/IEC 42001 | ISO/IEC 42001 clause 5.3 Roles, responsibilities and authorities | every account type |
| ISO/IEC 42001 | ISO/IEC 42001 A.3.2 AI roles and responsibilities | every account type |
| SOC 2 | SOC 2 CC6.1 Logical access security over protected information assets | every account type |
| CIS Controls | CIS Controls 5.5 Establish and Maintain an Inventory of Service Accounts | every account type |
The first clause, set out
ISO/IEC 27001 A.5.16Identity managementIdentities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.16.