Orphaned Account Checker

14. A secret where a label belongs

A value matching a recognised secret pattern (a password, a key or a token) was in the list. It was not read: it was replaced with "Secret removed" and the line number before anything was shown, and it reaches no export and no saved register. The list itself is somewhere a secret should not be.

The rule it applies

A cell matches a recognised secret pattern: a cloud access key, a private key block, a password, secret or token pair written with an equals sign, or a long run of hexadecimal or mixed-case base64 characters. The cell is replaced before anything renders.

A question for the account owner

Where else has this list been sent, and should that credential now be changed?

Clauses

2 across the regimes you tick
RegimeClauseRead on
ISO/IEC 27001ISO/IEC 27001 A.5.17 Authentication informationevery account type
NIST SP 800-53NIST SP 800-53 IA-5 Authenticator Managementevery account type

The first clause, set out

ISO/IEC 27001 A.5.17Authentication information

A management process is to control how authentication information is allocated and managed, and it includes telling personnel how to handle such information properly. Purpose (stated in ISO/IEC 27002:2022): ensures proper entity authentication and prevents authentication process failures. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.17.

What an auditor asks to see: Statement of Applicability entry for control A.5.17, showing inclusion or justified exclusion, implementation status and the risks it treats; Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use; Password policy and technical configuration showing length, complexity, reuse prevention, breached-password blocking and masked entry; Records of vendor default credentials being changed at installation
Where account lists usually fall short: Initial passwords are sent in clear text email or use a predictable pattern; Default vendor credentials remain on network devices or appliances; Shared account passwords are not changed when someone who knew them leaves; No check against known breached passwords is performed
Source: ISO/IEC 27001:2022 Annex A

See it on the specimenAll fourteen findings