12. Created with no approval recorded
The list has an approval or ticket column and this account's cell is blank: the list cannot show who asked for it or who agreed.
The rule it applies
The list has an approval or ticket column and this account's cell is blank. Built-in accounts, which nobody requested, are left out.
A question for the reviewer
Where is the request and the approval for this account?
Clauses
5 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| PCI DSS | PCI DSS 8.2.4 User ID lifecycle changes authorized | every account type |
| SOC 2 | SOC 2 CC6.2 Registering and authorising users before issuing credentials | every account type |
| CIS Controls | CIS Controls 6.1 Establish an Access Granting Process | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-2 Account Management | every account type |
| ISO/IEC 27001 | ISO/IEC 27001 A.5.18 Access rights | every account type |
The first clause, set out
PCI DSS 8.2.4User ID lifecycle changes authorizedAny addition, deletion or modification of a user ID, an authentication factor or another identifier object must be: authorized with appropriate approval; and carried out with only the privileges stated on the documented approval. The guidance stresses detecting IDs created or changed outside the normal process, since attackers often escalate an existing account or create new IDs. Applicability: covers every user account, whether held by employees, contractors, consultants, temporary staff or third-party vendors. Objective under the customized approach: no lifecycle event affecting a user ID or authentication factor can occur without appropriate authorization.