1. A leaver's own account is still enabled
The staff list says the person has left and their own account still reads as enabled. Each regime you tick has a clause on withdrawing access that is no longer needed, and PCI DSS 8.2.5 asks for a terminated user's access to be revoked immediately; the auditor samples leavers against enabled accounts first.
The rule it applies
The staff list is pasted, the account belongs to one person (a person or an administrator account, or a contractor whose own code is in the staff list), the staff list says that person left on or before the as-at date, and the account does not read as disabled. With no enabled column it is worded as a question.
A question for the account owner
Was this account disabled on the day the person left, and if not, what has it done since?
Clauses
8 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| PCI DSS | PCI DSS 8.2.5 Terminated users' access revoked immediately | every account type |
| CIS Controls | CIS Controls 6.2 Establish an Access Revoking Process | every account type |
| SOC 2 | SOC 2 CC6.3 Role-based access, least privilege and segregation of duties | every account type |
| SOC 2 | SOC 2 CC6.2 Registering and authorising users before issuing credentials | every account type |
| ISO/IEC 27001 | ISO/IEC 27001 A.5.18 Access rights | every account type |
| NIST SP 800-53 | NIST SP 800-53 PS-4 Personnel Termination | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-2 Account Management | every account type |
| NIS2 | NIS2 Art. 21(2)(i) Human resources security, access control policies and asset management | every account type |
The first clause, set out
PCI DSS 8.2.5Terminated users' access revoked immediatelyAccess for users who have been terminated must be revoked immediately. The testing procedures check both local and remote access lists for terminated IDs and confirm that any physical authentication factor, for example a token or smart card, has been deactivated or handed back. The guidance explains that a former employee or third party who keeps a working account, or an attacker who takes over an abandoned one, could reach cardholder data. Objective under the customized approach: accounts belonging to terminated users cannot be used.