2. Owner has left, or owner not recognised
A non-person account needs a person who answers for it. When that person has left, the account still works and nobody is asked about it; when the owner cannot be found in the staff list, the list cannot say who answers.
The rule it applies
The account is not a personal account, its owner names a person, and the staff list is pasted: when the list says that person has left it is a gap; when the owner is not in the list at all it is a question ("owner not recognised, confirm"). Without a staff list this finding never fires.
A question for the account owner
Who owns this account now, and should it still exist?
Clauses
5 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| ISO/IEC 27001 | ISO/IEC 27001 A.5.16 Identity management | every account type |
| CIS Controls | CIS Controls 5.5 Establish and Maintain an Inventory of Service Accounts | every account type |
| SOC 2 | SOC 2 CC6.2 Registering and authorising users before issuing credentials | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-2(3) Account management: Disable Accounts | every account type |
| NIS2 | NIS2 Art. 21(2)(i) Human resources security, access control policies and asset management | every account type |
The first clause, set out
ISO/IEC 27001 A.5.16Identity managementIdentities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.16.