Orphaned Account Checker

10. Not reviewed within the interval

Access that nobody has looked at within the interval is access nobody has confirmed. The interval is the one you set; with PCI DSS ticked, user accounts read against the six months of 7.2.4, and with CIS ticked, every account against the year of 6.8.

The rule it applies

The list has a last reviewed column, and this account's cell is blank or older than the interval you set (default 12 months) before the as-at date. With PCI DSS ticked, user accounts also fire at more than 6 months (7.2.4); with CIS Controls ticked, every account at more than 12 months (6.8). Exactly the interval never fires. Without the column, the finding does not fire and every line says the column is missing.

A question for the reviewer

Who reviews this account, and when is the next review due?

Clauses

8 across the regimes you tick
RegimeClauseRead on
ISO/IEC 27001ISO/IEC 27001 A.5.18 Access rightsevery account type
SOC 2SOC 2 CC6.2 Registering and authorising users before issuing credentialsevery account type
SOC 2SOC 2 CC6.3 Role-based access, least privilege and segregation of dutiesevery account type
CIS ControlsCIS Controls 6.8 Define and Maintain Role-Based Access Controlevery account type
NIST SP 800-53NIST SP 800-53 AC-6(7) Least privilege: Review of User Privilegesevery account type
NIS2NIS2 Art. 21(2)(i) Human resources security, access control policies and asset managementevery account type
PCI DSSPCI DSS 7.2.4 User accounts and privileges reviewed every six monthsuser accounts only
PCI DSSPCI DSS 7.2.5.1 Application and system account access reviewed periodicallyapplication and system accounts only

The first clause, set out

ISO/IEC 27001 A.5.18Access rights

Access rights to information and associated assets are to be granted, reviewed, changed and withdrawn in line with the access control rules and policy the organization has set. Purpose (stated in ISO/IEC 27002:2022): keeps access to information and assets defined and approved against what the business needs. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.18.

What an auditor asks to see: Statement of Applicability entry for control A.5.18, showing inclusion or justified exclusion, implementation status and the risks it treats; Access request records showing owner authorization, and management approval where required, before rights were activated; A central record of access rights per user identifier across logical and physical access; Periodic access review records including privileged access, with evidence that removals identified in the review were actioned; Leaver and mover reports showing timely removal or adjustment of rights, including keys, cards and subscriptions
Where account lists usually fall short: Access is cloned from a colleague's profile, carrying over excessive rights; Access reviews are rubber-stamped by managers without owner involvement; Physical access badges are not revoked on the same timeline as logical accounts; Temporary access granted for projects is never removed
Source: ISO/IEC 27001:2022 Annex A

See it on the specimenAll fourteen findings