4. Dormant for more than the threshold
An enabled account nobody has used is an open door nobody watches: a password change on it goes unnoticed. The threshold is the one you set; with CIS ticked, the 45 days of CIS 5.3 read beside it, and with PCI DSS ticked, the 90 days of 8.2.6 on user accounts.
The rule it applies
The account is enabled or its status is not recorded, it is not a break-glass account, and its last used date is more than the threshold you set (default 90 days) before the as-at date. With CIS Controls ticked, more than 45 days (CIS 5.3) also fires; with PCI DSS ticked, more than 90 days (8.2.6) fires on user accounts. An account never used fires when its created date is older than the same periods. Exactly the period never fires.
A question for the account owner
Is this account still needed, and if so by whom?
Clauses
4 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| CIS Controls | CIS Controls 5.3 Disable Dormant Accounts | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-2(3) Account management: Disable Accounts | every account type |
| ISO/IEC 27001 | ISO/IEC 27001 A.5.18 Access rights | every account type |
| PCI DSS | PCI DSS 8.2.6 Inactive accounts removed within 90 days | user accounts only |
The first clause, set out
CIS Controls 5.3Disable Dormant AccountsWhere supported, remove or disable any account that has been dormant for 45 days.