Orphaned Account Checker

1. A leaver's own account is still enabled

The staff list says the person has left and their own account still reads as enabled. Each regime you tick has a clause on withdrawing access that is no longer needed, and PCI DSS 8.2.5 asks for a terminated user's access to be revoked immediately; the auditor samples leavers against enabled accounts first.

The rule it applies

The staff list is pasted, the account belongs to one person (a person or an administrator account, or a contractor whose own code is in the staff list), the staff list says that person left on or before the as-at date, and the account does not read as disabled. With no enabled column it is worded as a question.

A question for the account owner

Was this account disabled on the day the person left, and if not, what has it done since?

Clauses

8 across the regimes you tick
RegimeClauseRead on
PCI DSSPCI DSS 8.2.5 Terminated users' access revoked immediatelyevery account type
CIS ControlsCIS Controls 6.2 Establish an Access Revoking Processevery account type
SOC 2SOC 2 CC6.3 Role-based access, least privilege and segregation of dutiesevery account type
SOC 2SOC 2 CC6.2 Registering and authorising users before issuing credentialsevery account type
ISO/IEC 27001ISO/IEC 27001 A.5.18 Access rightsevery account type
NIST SP 800-53NIST SP 800-53 PS-4 Personnel Terminationevery account type
NIST SP 800-53NIST SP 800-53 AC-2 Account Managementevery account type
NIS2NIS2 Art. 21(2)(i) Human resources security, access control policies and asset managementevery account type

The first clause, set out

PCI DSS 8.2.5Terminated users' access revoked immediately

Access for users who have been terminated must be revoked immediately. The testing procedures check both local and remote access lists for terminated IDs and confirm that any physical authentication factor, for example a token or smart card, has been deactivated or handed back. The guidance explains that a former employee or third party who keeps a working account, or an attacker who takes over an abandoned one, could reach cardholder data. Objective under the customized approach: accounts belonging to terminated users cannot be used.

What an auditor asks to see: HR termination list for the period reconciled against active account lists; Deprovisioning tickets with timestamps relative to termination dates; Remote access (VPN, SaaS, cloud) account listings checked for leavers; Token or smart card return and deactivation log
Where account lists usually fall short: Leavers disabled in the directory but still active in SaaS or VPN systems; Days elapse between termination and account revocation due to manual handoffs; Hardware tokens of departed staff never recovered or deactivated
Source: PCI DSS v4.0

See it on the specimenAll fourteen findings