Orphaned Account Checker

9. Shared or generic login used by people

A login several people use cannot tie an action to one of them, and its password does not change when one of them leaves.

The rule it applies

The account type is a shared or generic login, from the type column or assumed from the name.

A question for the reviewer

Who uses this login, and can each of them have their own account?

Clauses

6 across the regimes you tick
RegimeClauseRead on
PCI DSSPCI DSS 8.2.2 Shared and generic IDs only by exceptionevery account type
PCI DSSPCI DSS 8.2.1 Unique ID assigned to every userevery account type
ISO/IEC 27001ISO/IEC 27001 A.5.16 Identity managementevery account type
ISO/IEC 27001ISO/IEC 27001 A.8.15 Loggingevery account type
NIST SP 800-53NIST SP 800-53 AC-2(9) Account management: Restrictions on Use of Shared and Group Accountsevery account type
NIST SP 800-53NIST SP 800-53 IA-2 Identification and Authentication (Organizational Users)every account type

The first clause, set out

PCI DSS 8.2.2Shared and generic IDs only by exception

Group, shared or generic IDs, and any other shared authentication credentials, may be used only where needed as an exception, and must be managed so that: use of the ID is blocked unless an exceptional circumstance calls for it; use lasts only as long as the exceptional circumstance requires; a business justification is documented; management explicitly approves the use; the identity of the individual is verified before the account is made available; and every action taken is attributable to one individual user. The guidance suggests password vaults or controls like sudo, and gives a break-glass emergency account as an example of an exception. Applicability: not intended for point-of-sale terminal user accounts that are limited to a single card number per transaction. Objective under the customized approach: all actions carried out with group, shared or generic IDs can be attributed to an individual person.

What an auditor asks to see: Register of shared, group and generic accounts with business justification and management approval; Password vault checkout logs tying each use of a shared account to a named individual; Break-glass procedure and records of each emergency use with duration; Account configuration showing shared IDs disabled or locked outside approved use
Where account lists usually fall short: Root or built-in administrator password known by the whole team and used routinely; No record of who used a shared account at a given time; Shared account kept permanently enabled rather than for the duration of the exception; Justification documented but no explicit management approval
Source: PCI DSS v4.0

See it on the specimenAll fourteen findings