Orphaned Account Checker

12. Created with no approval recorded

The list has an approval or ticket column and this account's cell is blank: the list cannot show who asked for it or who agreed.

The rule it applies

The list has an approval or ticket column and this account's cell is blank. Built-in accounts, which nobody requested, are left out.

A question for the reviewer

Where is the request and the approval for this account?

Clauses

5 across the regimes you tick
RegimeClauseRead on
PCI DSSPCI DSS 8.2.4 User ID lifecycle changes authorizedevery account type
SOC 2SOC 2 CC6.2 Registering and authorising users before issuing credentialsevery account type
CIS ControlsCIS Controls 6.1 Establish an Access Granting Processevery account type
NIST SP 800-53NIST SP 800-53 AC-2 Account Managementevery account type
ISO/IEC 27001ISO/IEC 27001 A.5.18 Access rightsevery account type

The first clause, set out

PCI DSS 8.2.4User ID lifecycle changes authorized

Any addition, deletion or modification of a user ID, an authentication factor or another identifier object must be: authorized with appropriate approval; and carried out with only the privileges stated on the documented approval. The guidance stresses detecting IDs created or changed outside the normal process, since attackers often escalate an existing account or create new IDs. Applicability: covers every user account, whether held by employees, contractors, consultants, temporary staff or third-party vendors. Objective under the customized approach: no lifecycle event affecting a user ID or authentication factor can occur without appropriate authorization.

What an auditor asks to see: Joiner, mover and leaver tickets with approvals for a sample of accounts; Directory audit logs of account creation, change and deletion events; Comparison of granted privileges against privileges stated on each approval; Alerts or reports for accounts created outside the provisioning workflow
Where account lists usually fall short: Accounts created directly by administrators without a ticket; Temporary workers provisioned with more privileges than approved; Changes to authentication factors are not captured in any approval record
Source: PCI DSS v4.0

See it on the specimenAll fourteen findings