CIS Controls: what it asks of an account list
CIS Controls v8 set an account inventory with named owners (5.1, and 5.5 for service accounts) validated at least quarterly, dormant accounts disabled after 45 days (5.3), dedicated administrator accounts (5.4), access granting and revoking processes (6.1, 6.2), MFA for administrative access (6.5) and role-based access reviewed at least once a year (6.8). With CIS ticked, the 45 days of 5.3 and the year of 6.8 read beside your own periods.
When to tick it: tick it when the company works to the CIS Controls.
Findings that cite it
CIS Controls: every clause cited
8 of the 153 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
CIS Controls 5.1Establish and Maintain an Inventory of Accounts
Keep a register of every account the enterprise manages, covering both user and administrator accounts. At a minimum each entry should hold the person's name, the username, the start and end dates, and the department. Confirm that every active account is authorised on a regular cycle of at least once a quarter.
What an auditor asks to see: Account inventory showing name, username, start and end dates and department for user and admin accounts; Quarterly account validation records; Identity management standard naming who authorises accounts and the quarterly validation cadence; Reconciliation of the account inventory against the HR system showing mismatches and actions taken; Inventory entries for service and shared accounts with an accountable owner recorded
Where account lists usually fall short: Cloud and SaaS accounts missing from the inventory that only covers the directory; Quarterly validation done by IT alone without manager confirmation; End dates never recorded, so contractor accounts outlive their contracts
CIS Controls 5.3Disable Dormant Accounts
Where supported, remove or disable any account that has been dormant for 45 days.
What an auditor asks to see: Directory report of accounts inactive for 45 days or more; Automated disablement configuration or tickets showing dormant accounts disabled; Scheduled job or identity governance rule configuration disabling accounts after 45 days without logon; Exception list for dormant accounts retained, with owner approval; Cloud identity provider and SaaS inactive user reports checked alongside the directory
Where account lists usually fall short: Dormancy threshold set at 90 days instead of 45; Inactivity measured only in the on-premises directory, missing cloud-only accounts; Disabled accounts re-enabled on request without re-authorisation
CIS Controls 5.4Restrict Administrator Privileges to Dedicated Administrator Accounts
Confine administrator privileges on enterprise assets to accounts used only for administration. Everyday computing, for example web browsing, email and office productivity tools, is to be done from the user's main account without privileges.
What an auditor asks to see: List of dedicated admin accounts separate from users' everyday accounts; Privilege review showing everyday accounts hold no administrator rights; Membership exports of privileged groups showing only admin-designated accounts; Policy settings blocking email and web browsing for administrator accounts; Sample of administrators showing a separate standard account used for daily work
Where account lists usually fall short: Administrators using a single account for both daily work and privileged tasks; Local administrator rights granted to standard user accounts on workstations; Admin accounts with mailboxes and unrestricted internet access
CIS Controls 5.5Establish and Maintain an Inventory of Service Accounts
Keep a register of service accounts that records, at a minimum, the owning department, the date of review and the purpose. Review service accounts on a regular cycle of at least once a quarter to confirm that every active one is authorised.
What an auditor asks to see: Service account inventory with owning department, review date and purpose; Quarterly service account review records; Account management standard naming who owns each service account and requiring quarterly authorisation review; Directory export of accounts flagged as service accounts, reconciled against the inventory with unmatched entries listed; Last four quarterly review sign-offs with disabled or re-justified service accounts recorded per entry
Where account lists usually fall short: Service accounts created by application teams or vendors never entered in the inventory; Owning department still lists a team that was disbanded or a person who left; Quarterly review skipped or rubber-stamped with no account disabled in a year
CIS Controls 6.1Establish an Access Granting Process
Set up and use a process, automated where practical, that grants a user access to enterprise assets when they join, are given new rights, or change role.
What an auditor asks to see: Access request and approval workflow records for joiners, new rights and role changes; Sample provisioning tickets with manager approval; Access control procedure defining approvers for joiner, new-right and role-change requests; Identity governance or HR-driven provisioning workflow configuration showing automated grants from approved requests; Sample of joiners and movers traced from HR record to approved request to account creation date
Where account lists usually fall short: Access granted by administrators on verbal or chat requests with no approval record; Movers accumulate new rights while keeping the old role's access; Approval given by the requester's peer or the administrator doing the provisioning
CIS Controls 6.2Establish an Access Revoking Process
Set up and use a process, automated where practical, that removes a user's access to enterprise assets by disabling accounts at once when the user leaves, has rights withdrawn, or changes role. Disabling rather than deleting accounts can be needed to keep audit trails intact.
What an auditor asks to see: Leaver and role-change deprovisioning records showing accounts disabled promptly; Reconciliation of HR leaver lists against active accounts; Leaver procedure setting the disablement deadline after termination and when to disable rather than delete; HR-to-directory integration or scheduled job configuration that disables accounts on termination date; Sample of leavers comparing HR termination time with account disable time across directory, SaaS and VPN
Where account lists usually fall short: Leaver accounts disabled in the directory but still active in SaaS apps outside SSO; Contractor departures missed because contractors are not in the HR system; Accounts deleted outright, losing audit trail ownership needed for investigations
CIS Controls 6.5Require MFA for Administrative Access
Where supported, require MFA on every account with administrative access, on every enterprise asset, whether the asset is managed on site or by a third-party provider.
What an auditor asks to see: MFA configuration for all administrative accounts, on-site and third-party managed; Report of admin accounts with MFA enrolment status; Privileged access standard requiring MFA for all administrative logons, including provider-managed assets; PAM or identity provider policy export enforcing MFA on admin roles, cloud consoles and hypervisor management; Admin logon records sampled across on-site and hosted assets showing MFA used on each
Where account lists usually fall short: Break-glass or service admin accounts excluded from MFA without compensating controls; Network device and hypervisor consoles use local admin accounts with password only; Managed service provider staff administer assets through accounts not covered by enterprise MFA
CIS Controls 6.8Define and Maintain Role-Based Access Control
Define and keep role-based access control by working out and recording the access rights each role in the enterprise needs to perform its duties. Review access on enterprise assets on a regular cycle, at least once a year, to confirm that every privilege is authorised.
What an auditor asks to see: Role-based access matrix documenting rights per role; Access review records at the defined frequency, with changes actioned; Access control policy requiring role definitions and at least annual privilege recertification; Identity governance role definitions or group mappings exported from the directory for each role; Annual recertification campaign results showing reviewer decisions and revocations completed
Where account lists usually fall short: Roles defined too broadly so most users hold the same wide access; Direct permission grants outside roles never captured in the review; Managers approve every entitlement in recertification without revoking anything