3. No owner named, or a team named with no accountable person
An account with no owner, or one owned by a team or a mailbox with no named person accountable for it, has nobody who can say what it is for when the reviewer asks. A team can own an account; the list then needs the one person accountable for it (an accountable, approver or owner of record column). CIS Controls 5.1 and 5.5 describe an inventory that records an owner for each account.
The rule it applies
The account is not a personal account and its owner cell is blank, "unknown", "TBC" or similar, or names a team, a department or a mailbox with no accountable person named beside it. When an accountable, approver or owner of record column names a person for the team, this finding does not fire; with a staff list, that person is checked like any owner (left is finding 2, not in the list is a question).
A question for the reviewer
Which one person is accountable for this account and can say what it is for?
Clauses
6 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| ISO/IEC 27001 | ISO/IEC 27001 A.5.16 Identity management | every account type |
| ISO/IEC 27001 | ISO/IEC 27001 A.5.15 Access control | every account type |
| CIS Controls | CIS Controls 5.5 Establish and Maintain an Inventory of Service Accounts | every account type |
| CIS Controls | CIS Controls 5.1 Establish and Maintain an Inventory of Accounts | every account type |
| SOC 2 | SOC 2 CC6.1 Logical access security over protected information assets | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-2 Account Management | every account type |
The first clause, set out
ISO/IEC 27001 A.5.16Identity managementIdentities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.16.