Orphaned Account Checker

NIST SP 800-53: what it asks of an account list

NIST SP 800-53 Rev. 5 governs where a US federal system or contract applies it: account management (AC-2) with disabling of inactive and unassociated accounts (AC-2(3)), privileged accounts (AC-2(7)), shared and group accounts (AC-2(9)), least privilege (AC-6, AC-6(5), AC-6(7)), identifiers and authenticators (IA-2, IA-4, IA-5, IA-5(7), IA-9) and personnel termination (PS-4). Its periods are organization-defined; the periods here are the ones you set.

When to tick it: tick it when a US federal system or contract brings NIST SP 800-53 in.

Findings that cite it

FindingClause
1. A leaver's own account is still enabledNIST SP 800-53 PS-4 (every account type)
NIST SP 800-53 AC-2 (every account type)
2. Owner has left, or owner not recognisedNIST SP 800-53 AC-2(3) (every account type)
3. No owner named, or a team named with no accountable personNIST SP 800-53 AC-2 (every account type)
4. Dormant for more than the thresholdNIST SP 800-53 AC-2(3) (every account type)
5. Privileged, and orphaned or dormantNIST SP 800-53 AC-6 (every account type)
NIST SP 800-53 AC-6(5) (every account type)
NIST SP 800-53 AC-2(7) (every account type)
6. Password or key not changed within the period, or neverNIST SP 800-53 IA-5 (every account type)
7. Service or system account that allows interactive loginNIST SP 800-53 AC-6 (every account type)
8. Credential stored in code, a config file or a scriptNIST SP 800-53 IA-5(7) (every account type)
9. Shared or generic login used by peopleNIST SP 800-53 AC-2(9) (every account type)
NIST SP 800-53 IA-2 (every account type)
10. Not reviewed within the intervalNIST SP 800-53 AC-6(7) (every account type)
12. Created with no approval recordedNIST SP 800-53 AC-2 (every account type)
13. Vendor default or built-in account enabledNIST SP 800-53 IA-5 (every account type)
14. A secret where a label belongsNIST SP 800-53 IA-5 (every account type)

NIST SP 800-53: every clause cited

13 of the 1014 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

NIST SP 800-53 AC-2Account Management

a. Define and document the types of accounts allowed and specifically prohibited for use within the system; b. Assign account managers; c. Require [Assignment: organization-defined prerequisites and criteria] for group and role membership; d. Specify: 1. Authorized users of the system; 2. Group and role membership; and 3. Access authorizations (i.e., privileges) and [Assignment: organization-defined attributes (as required)] for each account; e. Require approvals by [Assignment: organization-defined personnel or roles] for requests to create accounts; f. Create, enable, modify, disable, and remove accounts in accordance with [Assignment: organization-defined policy, procedures, prerequisites, and criteria]; g. Monitor the use of accounts; h. Notify account managers and [Assignment: organization-defined personnel or roles] within: 1. [Assignment: organization-defined time period] when accounts are no longer required; 2. [Assignment: organization-defined time period] when users are terminated or transferred; and 3. [Assignment: organization-defined time period] when system usage or need-to-know changes for an individual; i. Authorize access to the system based on: 1. A valid access authorization; 2. Intended system usage; and 3. [Assignment: organization-defined attributes (as required)]; j. Review accounts for compliance with account management requirements [Assignment: organization-defined frequency]; k. Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and l. Align account management processes with personnel termination and transfer processes.

What an auditor asks to see: Access control policy; Personnel termination policy and procedure; Personnel transfer policy and procedure; Procedures for addressing account management; System design documentation; System configuration settings and associated documentation; List of active system accounts along with the name of the individual associated with each account; List of recently disabled system accounts and the name of the individual associated with each account; List of conditions for group and role membership; Test of Organizational processes for account management on the system; mechanisms for implementing account management
Where account lists usually fall short: Account types allowed and specifically prohibited under a are not defined, so shared and service accounts exist unchecked; Accounts of terminated or transferred users remain enabled because account managers are not notified as required by h.2
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 AC-2(3)Account management: Disable Accounts

Disable accounts within [Assignment: organization-defined time period] when the accounts: (a) Have expired; (b) Are no longer associated with a user or individual; (c) Are in violation of organizational policy; or (d) Have been inactive for [Assignment: organization-defined time period].

What an auditor asks to see: Access control policy; Procedures for addressing account management; System security plan; System design documentation; System configuration settings and associated documentation; System-generated list of accounts removed; System-generated list of emergency accounts disabled; System audit records; Test of Mechanisms for implementing account management functions
Where account lists usually fall short: Inactive accounts under condition (d) stay enabled because the organization-defined inactivity period is not configured or enforced; Accounts no longer associated with an individual, per (b), are found enabled after the organization-defined disable period
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 AC-2(7)Account management: Privileged User Accounts

(a) Establish and administer privileged user accounts in accordance with [Selection: a role-based access scheme; an attribute-based access scheme]; (b) Monitor privileged role or attribute assignments; (c) Monitor changes to roles or attributes; and (d) Revoke access when privileged role or attribute assignments are no longer appropriate.

What an auditor asks to see: Access control policy; Procedures addressing account management; System design documentation; System configuration settings and associated documentation; System-generated list of privileged user accounts and associated roles; Records of actions taken when privileged role assignments are no longer appropriate; System audit records; Audit tracking and monitoring reports; System monitoring records; Test of Mechanisms implementing account management functions; mechanisms monitoring privileged role assignments
Where account lists usually fall short: Privileged accounts are created ad hoc rather than under the selected role-based or attribute-based scheme; Changes to privileged roles or attributes are not monitored, and inappropriate privileged access is not revoked per (d)
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 AC-2(9)Account management: Restrictions on Use of Shared and Group Accounts

Only permit the use of shared and group accounts that meet [Assignment: organization-defined conditions for establishing shared and group accounts].

What an auditor asks to see: Access control policy; Procedures addressing account management; System design documentation; System configuration settings and associated documentation; System-generated list of shared/group accounts and associated roles; System audit records; System security plan; Test of Mechanisms implementing management of shared/group accounts
Where account lists usually fall short: Shared and group accounts are in use without the organization-defined conditions for establishing them; No record shows each shared or group account was checked against the defined conditions before approval
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 AC-6Least Privilege

Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.

What an auditor asks to see: Access control policy; Procedures addressing least privilege; List of assigned access authorizations (user privileges); System configuration settings and associated documentation; System audit records; System security plan; Test of Mechanisms implementing least privilege functions
Where account lists usually fall short: Users and service processes hold permissions beyond what their assigned tasks require, with no evidence of task-based access design; Default broad group memberships grant all staff write access to shared resources irrespective of their organizational tasks
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 AC-6(5)Least privilege: Privileged Accounts

Restrict privileged accounts on the system to [Assignment: organization-defined personnel or roles].

What an auditor asks to see: Access control policy; Procedures addressing least privilege; List of system-generated privileged accounts; List of system administration personnel; System configuration settings and associated documentation; System audit records; System security plan; Test of Mechanisms implementing least privilege functions
Where account lists usually fall short: Privileged accounts are held by personnel outside the organization-defined roles, including developers and help desk staff; The personnel or roles permitted to hold privileged accounts were never defined, so no baseline exists to validate privileged access
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 AC-6(7)Least privilege: Review of User Privileges

(a) Review [Assignment: organization-defined frequency] the privileges assigned to [Assignment: organization-defined roles or classes of users] to validate the need for such privileges; and (b) Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs.

What an auditor asks to see: Access control policy; Procedures addressing least privilege; List of system-generated roles or classes of users and assigned privileges; System design documentation; System configuration settings and associated documentation; Validation reviews of privileges assigned to roles or classes or users; Records of privilege removals or reassignments for roles or classes of users; System audit records; System security plan; Test of Mechanisms implementing review of user privileges
Where account lists usually fall short: Privileges assigned to the defined roles or classes of users are not reviewed at the organization-defined frequency, and no review evidence exists; Reviews under (b) identify unneeded privileges, but they are not reassigned or removed to reflect current business needs
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 IA-2Identification and Authentication (Organizational Users)

Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.

What an auditor asks to see: Identification and authentication policy; Procedures addressing user identification and authentication; System security plan, system design documentation; System configuration settings and associated documentation; System audit records; List of system accounts; Test of Organizational processes for uniquely identifying and authenticating users; mechanisms supporting and/or implementing identification and authentication capabilities
Where account lists usually fall short: Shared or generic accounts are used by organizational users without unique identification of each individual; Processes acting on behalf of users run under service identities not associated with the initiating user's identity
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 IA-4Identifier Management

Manage system identifiers by: a. Receiving authorization from [Assignment: organization-defined personnel or roles] to assign an individual, group, role, service, or device identifier; b. Selecting an identifier that identifies an individual, group, role, service, or device; c. Assigning the identifier to the intended individual, group, role, service, or device; and d. Preventing reuse of identifiers for [Assignment: organization-defined time period].

What an auditor asks to see: Identification and authentication policy; Procedures addressing identifier management; Procedures addressing account management; System security plan; System design documentation; System configuration settings and associated documentation; List of system accounts; List of identifiers generated from physical access control devices; Test of Mechanisms supporting and/or implementing identifier management
Where account lists usually fall short: Identifiers are assigned without authorization from the organization-defined personnel or roles, per a; Identifiers of departed users are reused before the organization-defined period elapses, contrary to d
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 IA-5Authenticator Management

Manage system authenticators by: a. Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator; b. Establishing initial authenticator content for any authenticators issued by the organization; c. Ensuring that authenticators have sufficient strength of mechanism for their intended use; d. Establishing and implementing administrative procedures for initial authenticator distribution, for lost or compromised or damaged authenticators, and for revoking authenticators; e. Changing default authenticators prior to first use; f. Changing or refreshing authenticators [Assignment: organization-defined time period by authenticator type] or when [Assignment: organization-defined events] occur; g. Protecting authenticator content from unauthorized disclosure and modification; h. Requiring individuals to take, and having devices implement, specific controls to protect authenticators; and i. Changing authenticators for group or role accounts when membership to those accounts changes.

What an auditor asks to see: Identification and authentication policy; System security plan; Addressing authenticator management; System design documentation; System configuration settings and associated documentation; List of system authenticator types; Change control records associated with managing system authenticators; System audit records; Test of Mechanisms supporting and/or implementing authenticator management capability
Where account lists usually fall short: Default authenticators on devices and applications were not changed prior to first use, per e; Authenticators for group or role accounts were not changed when account membership changed, contrary to i
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 IA-5(7)Authenticators: No Embedded Unencrypted Static Authenticators

Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.

What an auditor asks to see: Identification and authentication policy; System security plan; Procedures addressing authenticator management; System design documentation; System configuration settings and associated documentation; Logical access scripts; Application code reviews for detecting unencrypted static authenticators; Test of Mechanisms supporting and/or implementing authenticator management capability; mechanisms implementing authentication in applications
Where account lists usually fall short: Unencrypted static authenticators such as passwords or keys are embedded in application code or scripts; No code scanning checks applications and static storage for embedded credentials
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 IA-9Service Identification and Authentication

Uniquely identify and authenticate [Assignment: organization-defined system services and applications] before establishing communications with devices, users, or other services or applications.

What an auditor asks to see: Identification and authentication policy; Procedures addressing service identification and authentication; System security plan; System design documentation; Security safeguards used to identify and authenticate system services; System configuration settings and associated documentation; System audit records; Test of Security safeguards implementing service identification and authentication capabilities
Where account lists usually fall short: Defined services and applications communicate without unique identification and authentication; The services and applications requiring authentication before communication were never defined
Source: NIST SP 800-53 Rev. 5
NIST SP 800-53 PS-4Personnel Termination

Upon termination of individual employment: a. Disable system access within [Assignment: organization-defined time period]; b. Terminate or revoke any authenticators and credentials associated with the individual; c. Conduct exit interviews that include a discussion of [Assignment: organization-defined information security topics]; d. Retrieve all security-related organizational system-related property; and e. Retain access to organizational information and systems formerly controlled by terminated individual.

What an auditor asks to see: Personnel security policy; Procedures addressing personnel termination; Records of personnel termination actions; List of system accounts; Records of terminated or revoked authenticators/credentials; Records of exit interviews; System security plan; Test of Organizational processes for personnel termination; mechanisms supporting and/or implementing personnel termination notifications; mechanisms for disabling system access/revoking authenticators
Where account lists usually fall short: System access for terminated individuals is not disabled within the organization-defined time period after departure; Exit interviews are not conducted and security-related property such as badges and tokens is not retrieved on termination
Source: NIST SP 800-53 Rev. 5