Orphaned Account Checker

7. Service or system account that allows interactive login

A service account a person can sign in to is a shared login by another name: actions under it cannot be tied to one person.

The rule it applies

An application or system account (service account, API key, OAuth client, agent, automation or workload identity) whose interactive login column reads yes.

A question for the account owner

Who signs in to this account interactively, and can interactive login be turned off?

Clauses

5 across the regimes you tick
RegimeClauseRead on
ISO/IEC 27001ISO/IEC 27001 A.8.2 Privileged access rightsevery account type
ISO/IEC 27001ISO/IEC 27001 A.8.15 Loggingevery account type
NIST SP 800-53NIST SP 800-53 AC-6 Least Privilegeevery account type
PCI DSSPCI DSS 8.6.1 Interactive use of system accounts controlledapplication and system accounts only
PCI DSSPCI DSS 7.2.5 Application and system accounts least privilegeapplication and system accounts only

The first clause, set out

ISO/IEC 27001 A.8.2Privileged access rights

The granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2.

What an auditor asks to see: Statement of Applicability entry for control A.8.2, showing inclusion or justified exclusion, implementation status and the risks it treats; An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry; Privileged access management configuration showing time-limited elevation, step-up authentication and session recording; Privileged access review records performed periodically and after organizational changes
Where account lists usually fall short: Administrators use their privileged account for email and web browsing; Shared generic administrator accounts are used with no individual accountability; Privileged rights are standing and never expire; Service accounts with administrative rights are excluded from reviews
Source: ISO/IEC 27001:2022 Annex A

See it on the specimenAll fourteen findings