Orphaned Account Checker

5. Privileged, and orphaned or dormant

The same gap on an account with administrative rights: nobody answers for the widest access in the list, or it sits unused with its rights intact.

The rule it applies

The account is privileged (its privileged column reads yes, its member-of column names an administrative group, or it is an administrator, break-glass or built-in administrator account) and it carries finding 1, 2, 3 or 4.

A question for the reviewer

Who holds these rights today, and do they still need them?

Clauses

6 across the regimes you tick
RegimeClauseRead on
ISO/IEC 27001ISO/IEC 27001 A.8.2 Privileged access rightsevery account type
CIS ControlsCIS Controls 5.4 Restrict Administrator Privileges to Dedicated Administrator Accountsevery account type
NIST SP 800-53NIST SP 800-53 AC-6 Least Privilegeevery account type
NIST SP 800-53NIST SP 800-53 AC-6(5) Least privilege: Privileged Accountsevery account type
NIST SP 800-53NIST SP 800-53 AC-2(7) Account management: Privileged User Accountsevery account type
SOC 2SOC 2 CC6.3 Role-based access, least privilege and segregation of dutiesevery account type

The first clause, set out

ISO/IEC 27001 A.8.2Privileged access rights

The granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.2.

What an auditor asks to see: Statement of Applicability entry for control A.8.2, showing inclusion or justified exclusion, implementation status and the risks it treats; An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry; Privileged access management configuration showing time-limited elevation, step-up authentication and session recording; Privileged access review records performed periodically and after organizational changes
Where account lists usually fall short: Administrators use their privileged account for email and web browsing; Shared generic administrator accounts are used with no individual accountability; Privileged rights are standing and never expire; Service accounts with administrative rights are excluded from reviews
Source: ISO/IEC 27001:2022 Annex A

See it on the specimenAll fourteen findings