9. Shared or generic login used by people
A login several people use cannot tie an action to one of them, and its password does not change when one of them leaves.
The rule it applies
The account type is a shared or generic login, from the type column or assumed from the name.
A question for the reviewer
Who uses this login, and can each of them have their own account?
Clauses
6 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| PCI DSS | PCI DSS 8.2.2 Shared and generic IDs only by exception | every account type |
| PCI DSS | PCI DSS 8.2.1 Unique ID assigned to every user | every account type |
| ISO/IEC 27001 | ISO/IEC 27001 A.5.16 Identity management | every account type |
| ISO/IEC 27001 | ISO/IEC 27001 A.8.15 Logging | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-2(9) Account management: Restrictions on Use of Shared and Group Accounts | every account type |
| NIST SP 800-53 | NIST SP 800-53 IA-2 Identification and Authentication (Organizational Users) | every account type |
The first clause, set out
PCI DSS 8.2.2Shared and generic IDs only by exceptionGroup, shared or generic IDs, and any other shared authentication credentials, may be used only where needed as an exception, and must be managed so that: use of the ID is blocked unless an exceptional circumstance calls for it; use lasts only as long as the exceptional circumstance requires; a business justification is documented; management explicitly approves the use; the identity of the individual is verified before the account is made available; and every action taken is attributable to one individual user. The guidance suggests password vaults or controls like sudo, and gives a break-glass emergency account as an example of an exception. Applicability: not intended for point-of-sale terminal user accounts that are limited to a single card number per transaction. Objective under the customized approach: all actions carried out with group, shared or generic IDs can be attributed to an individual person.