Orphaned Account Checker

3. No owner named, or a team named with no accountable person

An account with no owner, or one owned by a team or a mailbox with no named person accountable for it, has nobody who can say what it is for when the reviewer asks. A team can own an account; the list then needs the one person accountable for it (an accountable, approver or owner of record column). CIS Controls 5.1 and 5.5 describe an inventory that records an owner for each account.

The rule it applies

The account is not a personal account and its owner cell is blank, "unknown", "TBC" or similar, or names a team, a department or a mailbox with no accountable person named beside it. When an accountable, approver or owner of record column names a person for the team, this finding does not fire; with a staff list, that person is checked like any owner (left is finding 2, not in the list is a question).

A question for the reviewer

Which one person is accountable for this account and can say what it is for?

Clauses

6 across the regimes you tick
RegimeClauseRead on
ISO/IEC 27001ISO/IEC 27001 A.5.16 Identity managementevery account type
ISO/IEC 27001ISO/IEC 27001 A.5.15 Access controlevery account type
CIS ControlsCIS Controls 5.5 Establish and Maintain an Inventory of Service Accountsevery account type
CIS ControlsCIS Controls 5.1 Establish and Maintain an Inventory of Accountsevery account type
SOC 2SOC 2 CC6.1 Logical access security over protected information assetsevery account type
NIST SP 800-53NIST SP 800-53 AC-2 Account Managementevery account type

The first clause, set out

ISO/IEC 27001 A.5.16Identity management

Identities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.16.

What an auditor asks to see: Statement of Applicability entry for control A.5.16, showing inclusion or justified exclusion, implementation status and the risks it treats; Identity management procedure covering creation, verification, activation, change, disablement and removal; Evidence that identities are verified against trusted documents before issue; A register of shared identities with the business justification and approval for each; A register of non-human identities (service accounts, machine identities) with segregated approval and an independent oversight record
Where account lists usually fall short: Generic shared accounts exist without documented justification or approval; Service accounts have no owner and no periodic oversight; Identities of leavers remain enabled for weeks because HR notifications are not integrated; The same person holds several identities in one directory, undermining accountability
Source: ISO/IEC 27001:2022 Annex A

See it on the specimenAll fourteen findings