7. Service or system account that allows interactive login
A service account a person can sign in to is a shared login by another name: actions under it cannot be tied to one person.
The rule it applies
An application or system account (service account, API key, OAuth client, agent, automation or workload identity) whose interactive login column reads yes.
A question for the account owner
Who signs in to this account interactively, and can interactive login be turned off?
Clauses
5 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| ISO/IEC 27001 | ISO/IEC 27001 A.8.2 Privileged access rights | every account type |
| ISO/IEC 27001 | ISO/IEC 27001 A.8.15 Logging | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-6 Least Privilege | every account type |
| PCI DSS | PCI DSS 8.6.1 Interactive use of system accounts controlled | application and system accounts only |
| PCI DSS | PCI DSS 7.2.5 Application and system accounts least privilege | application and system accounts only |
The first clause, set out
ISO/IEC 27001 A.8.2Privileged access rightsThe granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2.