13. Vendor default or built-in account enabled
A built-in or vendor default account is known to anyone who has read the product's manual; one left enabled is the first thing tried.
The rule it applies
The account is a built-in or vendor default account (from the type column, or a whole account name such as admin, root, sa or guest) and does not read as disabled.
A question for the account owner
Is this default account used, and if so has its default password been changed?
Clauses
3 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| PCI DSS | PCI DSS 2.2.2 Vendor default accounts managed | every account type |
| ISO/IEC 27001 | ISO/IEC 27001 A.5.17 Authentication information | every account type |
| NIST SP 800-53 | NIST SP 800-53 IA-5 Authenticator Management | every account type |
The first clause, set out
PCI DSS 2.2.2Vendor default accounts managedVendor default accounts must be handled as follows: (a) where a vendor default account will be used, its default password is changed in line with Requirement 8.3.6; and (b) where it will stay unused, the account is disabled or deleted. Applicability: every vendor default account and password is covered, for example those of operating systems, security software, application and system accounts, POS terminals, payment applications and SNMP defaults; it also applies to components not installed in the entity's environment, such as CDE software and applications consumed through a cloud subscription. Objective under the customized approach: default passwords cannot be used to access system components.